up1.nhksoftware.net

Starline Alliance LTD.

Domain Information

The domain up1.nhksoftware.net registered by Starline Alliance LTD. was initially registered in October of 2014 through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Haarlem, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Friday, October 10, 2014

Expires date:
Saturday, October 10, 2015

Updated date:
Friday, October 10, 2014

ASN:
AS62403 DISKGROUP Disk Group Ltd.,CZ

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ROSA.X, PUP.Installer.ROSA.Y, PUP.Installer.ROSA.EE, PUP.Installer.ROSA.i, PUP.Installer.ROSA.g, PUP.ROSA.Installer (M), PUP (M)
100.00%

Avira AntiVirus
APPL/Downloader.Gen9, APPL/Downloader.Gen4, PUA/bmMedia.Gen4
19.57%

AVG
Generic
19.57%

Agnitum Outpost
Riskware.Agent
17.39%

IKARUS anti.virus
AdWare.Agent, Win32.SuspectCrc, PUA.bmMedia, not-a-virus:AdWare.Winner
15.22%

Dr.Web
Trojan.Packed.29079
13.04%

avast!
Win32:Malware-gen, Win32:Rootkit-gen [Rtk]
13.04%

ESET NOD32
Win32/bmMedia.CP (variant), Win32/bmMedia.CS, Win32/bmMedia.DH (variant), Win32/bmMedia.CG
10.87%

VIPRE Antivirus
Threat.4150696
10.87%

NANO AntiVirus
Trojan.Win32.BmMedia.djhbvb, Trojan.Win32.BmMedia.didzhh, Trojan.Win32.XPACK.djrkrh
10.87%

ESET NOD32
Win32/bmMedia.BY potentially unwanted application, Win32/bmMedia.CS potentially unwanted application, Win32/bmMedia.CG potentially unwanted application
10.87%

Emsisoft Anti-Malware
Adware.Agent.ONV, Gen:Variant.Kazy.483613
8.70%

Norman
Adware.Agent.ONV, Gen:Variant.Kazy.483613, Kelihos.BW
8.70%

MicroWorld eScan
Adware.Agent.ONV, Gen:Variant.Kazy.483613
8.70%

F-Prot
W32/A-e6de93f4, W32/A-12625e94
8.70%

The domain up1.nhksoftware.net has been seen to resolve to the following IP address.

October 20, 2014

File downloads found at URLs served by up1.nhksoftware.net.

 
Latest 30 of 55 download URLs

URL:
http://up1.nhksoftware.net/

Web server:
nginx