rootkinds.net

Ostap Kosilko

Domain Information

The domain rootkinds.net registered by Ostap Kosilko was initially registered in January of 2015 through 1 & 1 INTERNET AG. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Manassas, Virginia within the United States which resides on the Leaseweb USA, Inc. network.
Registrar:
1&1 INTERNET SE

Server location:
Virginia, United States (US)

Create date:
Wednesday, January 14, 2015

Expires date:
Saturday, January 14, 2017

Updated date:
Thursday, February 18, 2016

ASN:
AS30633 LEASEWEB-US - Leaseweb USA, Inc.,US

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP, PUP.WebPick, PUP.WebPick.AndreyHmelnikov (M), PUP.WebPick.AndreyHm (M), Adware.Generic.AT (M), PUP.WebPick (M)
59.18%

ESET NOD32
Win32/Adware.MultiPlug.EP application, Win32/Adware.MultiPlug.ES application, Win32/Ramnit.A virus
55.10%

AVG
Adware Generic6.MSZ, Adware Generic6.MUG, Adware Generic6.NBJ, Adware Generic6.MVQ, Adware Generic6.MWB, Adware Generic6.MUA
51.02%

Emsisoft Anti-Malware
Gen:Variant.Adware.Multiplug.11, Gen:Variant.Adware.Kazy.552220, Gen:Variant.Adware.Mikey.7658, Gen:Variant.Adware.Mplug.30
46.94%

avast!
Win32:Malware-gen, Win32:MultiPlug-SY [PUP], Win32:MultiPlug-SM [PUP], Win32:MultiPlug-SK [PUP], Win32:MultiPlug-TC [PUP], Win32:FakeDownload-E [PUP]
46.94%

McAfee
Program.MultiPlug-FVH, Program.MultiPlug-FVQ, Program.MultiPlug-FVJ, Program.MultiPlug-FQW
42.86%

F-Secure
Gen:Variant.Adware.Multiplug.11, Gen:Variant.Adware.Kazy.552220, Gen:Variant.Adware.Mikey.7658, Gen:Variant.Adware.Mplug
30.61%

Norman
Gen:Trojan.Heur.JP.evW@aSAip@gi, Gen:Variant.Adware.Multiplug.11, Win32.Ramnit
28.57%

Sophos
MultiPlug, PUA 'MultiPlug' (of type Adware)
26.53%

Lavasoft Ad-Aware
Gen:Variant.Adware.Multiplug.11, Gen:Variant.Adware.Kazy.552220, Gen:Variant.Adware.Mikey.7658, Gen:Variant.Adware.Mplug.30
24.49%

MicroWorld eScan
Gen:Variant.Adware.Multiplug.11, Gen:Variant.Adware.Kazy.552220, Gen:Variant.Adware.Mikey.7658, Gen:Variant.Adware.Mplug.30
24.49%

K7 AntiVirus
Unwanted-Program
24.49%

NANO AntiVirus
Riskware.Win32.MultiPlug.dnqlow, Riskware.Win32.MultiPlug.dnvmvm, Riskware.Win32.MultiPlug.dnvomt, Riskware.Win32.MultiPlug.dnvlvi
24.49%

F-Prot
W32/S-5a9b25b4, W32/S-f6576d9c, W32/S-05e718fa, W32/S-42f8a357, W32/S-fb69ed61, W32/Ramnit.B
24.49%

Bitdefender
Gen:Variant.Adware.Multiplug.11, Gen:Variant.Adware.Kazy.552220, Gen:Variant.Adware.Mikey.7658, Gen:Variant.Adware.Mplug.30
24.49%

The domain rootkinds.net has been seen to resolve to the following 2 IP addresses.

ec2-52-35-237-61.us-west-2.compute.amazonaws.com
January 30, 2016

hosted-by.leaseweb.com
March 20, 2015

File downloads found at URLs served by rootkinds.net.

 
Latest 30 of 55 download URLs

URL:
http://rootkinds.net/

Title:
“download”

Web server:
openresty