update.idmsilent.net

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain update.idmsilent.net is registered by proxy through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM and was originally registered in November of 2012. Currently this domain has been known to host various forms of malware. The hosted servers are located in Roosendaal, Noord-Brabant within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Noord-Brabant, Netherlands (NL)

Create date:
Monday, November 19, 2012

Expires date:
Saturday, November 19, 2016

Updated date:
Friday, March 18, 2016

ASN:
AS43350 NFORCE NFOrce Entertainment BV,NL

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Bkav FE
W32.StawingmanLTAAAI.Trojan
100.00%

MicroWorld eScan
Trojan.GenericKD.1609564
100.00%

nProtect
Trojan.GenericKD.1609564
100.00%

Quick Heal
Trojan.MSI.r3
100.00%

McAfee
RDN/Generic.grp!ha
100.00%

Malwarebytes
Trojan.MSIL
100.00%

K7 AntiVirus
Trojan
100.00%

Agnitum Outpost
Trojan.BitMiner
100.00%

Trend Micro House Call
TROJ_GEN.R0CBC0PCN14
100.00%

avast!
Win32:Inject-BHU [Trj]
100.00%

Kaspersky
Trojan.MSIL.BitMiner
100.00%

Bitdefender
Trojan.GenericKD.1609564
100.00%

Lavasoft Ad-Aware
Trojan.GenericKD.1609564
100.00%

Sophos
Troj/MSIL-QF
100.00%

Comodo Security
UnclassifiedMalware
100.00%

The domain update.idmsilent.net has been seen to resolve to the following IP address.

.
April 5, 2016

File downloads found at URLs served by update.idmsilent.net.

32 / 68    (Malware)

URL:
http://update.idmsilent.net/

Title:
“Page Loading...”

Web server:
Apache/2.2.15 (CentOS) (PHP/5.3.3)