kiadown.me

WhoisGuard, Inc.  (Proxy Registrant)

Domain Information

The domain kiadown.me is registered by proxy through NameCheap, Inc.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Beauharnois, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Registrar:
NameCheap, Inc.

Server location:
Quebec, Canada (CA)

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (70% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.YuBao (M), PUP.Vittalia.InstallA.Installer (M), Adware.Bundler (M)
68.75%

F-Prot
W32/Adware.ALMA (exact, not disinfectable), W32/NetFilter-PUA.B, W32/NetFilter-PUA.B (exact, not disinfectable)
50.00%

Microsoft Security Essentials
Threat.Undefined, BrowserModifier:Win32/Wolerngi
31.25%

ESET NOD32
multiple threats, Win32/Obfuscated.NGJ trojan
31.25%

Dr.Web
Detection.Undefined, Trojan.Zadved.545
25.00%

Emsisoft Anti-Malware
Dropped:Adware.Agent.PPG, Trojan.Generic.15339704
18.75%

AVG
Adware Generic6.TGA, Generic7
18.75%

McAfee
Trojan.PUP-RFTY, Artemis!5B46443F5326
12.50%

Norman
Dropped:Adware.Agent.PPG
6.25%

MicroWorld eScan
Trojan.Generic.15339704
6.25%

nProtect
Trojan.Generic.15339704
6.25%

Quick Heal
SftwrBndlr.NSIS.Yontoo.C
6.25%

Malwarebytes
PUP.Optional.BrAdware
6.25%

Bitdefender
Trojan.Generic.15339704
6.25%

K7 AntiVirus
Adware
6.25%

The domain kiadown.me has been seen to resolve to the following 2 IP addresses.

108.ip-158-69-217.net
August 29, 2016

July 17, 2016

File downloads found at URLs served by kiadown.me.

0 / 68
http://kiadown.me/.../291014_nj.exe  (nnrvvmvhlfn7jwgvrryl9gb2mauknnrvvmvhlfn7jwgvrryl9gb2mauknnrvvmvhlfn7jwgvrryl9gb2mauk_nj.exe)

0 / 68
http://kiadown.me/.../291014_nj.exe  (nfbgwzurie4kcdswxdjpan56onfbgwzurie4kcdswxdjpan56onfbgwzurie4kcdswxdjpan56o_nj.exe)

1 / 68      (PUP)
http://kiadown.me/.../310714_a14.exe  (g0ltewfjr1xpyirdhmtmbvgooj2gg0ltewfjr1xpyirdhmtmbvgooj2g_a14.exe)

1 / 68      (PUP)
http://kiadown.me/.../310714_a14.exe  (nfbgwzurie4kcdswxdjpan56onfbgwzurie4kcdswxdjpan56o_a14.exe)

3 / 68      (Malware)
http://kiadown.me/.../291014_nj.exe  (8e7efdc7e74271228ca301a0db31f578)

1 / 68      (PUP)
http://kiadown.me/.../310714_a14.exe  (f3mbwf4t7smpfn5oihvzeecsnaqr5f3mbwf4t7smpfn5oihvzeecsnaqr5_a14.exe)

0 / 68
http://kiadown.me/.../310714_br.exe  (ruadj8q9hdozbiku4sp3kxcwlsxqjruadj8q9hdozbiku4sp3kxcwlsxqjruadj8q9hdozbiku4sp3kxcwlsxqj_br.exe)

7 / 68      (Malware)
http://kiadown.me/.../291014_nj.exe  (e89e0235246e314c154a374f1df6864c)

0 / 68
http://kiadown.me/.../280815_cr.exe  (2mtgcvotm0vr7ttqqmio3ehwzwa_cr.exe)

1 / 68      (PUP)
http://kiadown.me/.../310714_a14.exe  (uuisetcbg7e3upyafiyidp40jyrnquuisetcbg7e3upyafiyidp40jyrnq_a14.exe)

1 / 68      (PUP)
http://kiadown.me/.../310714_a14.exe  (fdlq38bdapaqc1zta9rhrnmpfdlq38bdapaqc1zta9rhrnmp_a14.exe)

1 / 68      (PUP)
http://kiadown.me/.../310714_a14.exe  (fdlq38bdapaqc1zta9rhrnmpfdlq38bdapaqc1zta9rhrnmp_a14.exe)

1 / 68      (PUP)
http://kiadown.me/.../310714_a14.exe  (tjn4mtd50imznipnircwjij3cptjn4mtd50imznipnircwjij3cp_a14.exe)

26 / 68    (PUP)
http://kiadown.me/.../291014_nj.exe  (hpaqjo9xm1lxijbpbkjig1nphhpaqjo9xm1lxijbpbkjig1nphhpaqjo9xm1lxijbpbkjig1nph_nj.exe)

8 / 68      (PUP)
http://kiadown.me/.../280815_cr.exe  (b829a6d3c3a4956c6726b43bfbe5258a)

1 / 68      (PUP)
http://kiadown.me/.../310714_a14.exe  (nfbgwzurie4kcdswxdjpan56onfbgwzurie4kcdswxdjpan56o_a14.exe)

0 / 68
http://kiadown.me/.../310714_br.exe  (fdlq38bdapaqc1zta9rhrnmpfdlq38bdapaqc1zta9rhrnmpfdlq38bdapaqc1zta9rhrnmp_br.exe)

0 / 68
http://kiadown.me/.../291014_nj.exe  (4eirusbvegtlp47ffvnng66bjpye4eirusbvegtlp47ffvnng66bjpye4eirusbvegtlp47ffvnng66bjpye_nj.exe)

6 / 68      (PUP)
http://kiadown.me/.../280815_cr.exe  (f1c07d7c53f79fdc3ff63fa7fe027c9d)

1 / 68      (PUP)
http://kiadown.me/.../310714_mb.exe  (fdlq38bdapaqc1zta9rhrnmp_has.exe)

1 / 68      (Adware)

0 / 68
http://kiadown.me/.../310714_mb.exe  (bqmshqlszf3ibm7ekfrgem_has.exe)

2 / 68      (PUP)
http://kiadown.me/.../310714_a14.exe  (ruadj8q9hdozbiku4sp3kxcwlsxqjruadj8q9hdozbiku4sp3kxcwlsxqj_a14.exe)

URL:
http://kiadown.me/

Title:
“Em manutencao”

Web server:
nginx/1.0.15 (PHP/5.6.13)

30 of 43 related domains