www.adskdoom.info

Miro Shona

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GoDaddy.com, LLC

Server location:
Arizona, United States (US)

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Bkav FE
W32.KirapaL.Trojan, W32.HfsAdware, HW32.Packed, W32.HfsAutoB
83.33%

MicroWorld eScan
Gen:Variant.Adware.Graftor.173198, Gen:Variant.Zusy.113278, Gen:Variant.Graftor.180743, Gen:Variant.Zusy.133389
83.33%

K7 AntiVirus
Adware , Trojan
83.33%

Bitdefender
Gen:Variant.Adware.Graftor.173198, Gen:Variant.Zusy.113278, Gen:Variant.Graftor.180743, Gen:Variant.Zusy.133389
83.33%

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.173198, Gen:Variant.Zusy.113278, Gen:Variant.Graftor.180743, Gen:Variant.Zusy.133389
83.33%

Avira AntiVirus
Adware/Vonteera.1139792, Adware/Vonteera.2155600, ADWARE/Vonteera.2713088, Adware/Vonteera.4536320, ADWARE/Vonteera.1640016
83.33%

G Data
Gen:Variant.Adware.Graftor.173198, Gen:Variant.Zusy.113278, Gen:Variant.Graftor.180743, Trojan.GenericKD.2234822
83.33%

AhnLab V3 Security
Adware/Win32.MultiPlug, Adware/Win32.Vonteera
83.33%

McAfee
Artemis!623018FC95AD, Artemis!F4A06CD0B5BD, Artemis!1B0D3A6C6B46, Artemis!1CB8C03FB510, Artemis!ACFFBA2B2A89
83.33%

Fortinet FortiGate
Riskware/Vonteera, Adware/Vonteera, W32/Vonteera.K, Adware/Generic
83.33%

AVG
Win32/DH, Generic, Generic6
83.33%

Panda Antivirus
Trj/Genetic.gen, Trj/CI.A, Generic Suspicious
83.33%

Qihoo 360 Security
HEUR/QVM41.1.Malware.Gen, HEUR/QVM19.1.Malware.Gen
83.33%

Trend Micro House Call
TROJ_GEN.R047H07BA15, TROJ_GEN.R0C1H07BI15, TROJ_GEN.R031C0ECN15, Suspicious_GEN.F47V0319
66.67%

avast!
Win32:Adware-gen [Adw]
66.67%

The domain www.adskdoom.info has been seen to resolve to the following 2 IP addresses.

May 20, 2016

ip-50-63-202-65.ip.secureserver.net
February 28, 2016

File downloads found at URLs served by www.adskdoom.info.

25 / 68    (PUP)

1 / 68      (Adware)

31 / 68    (Adware)

31 / 68    (Adware)
http://www.adskdoom.info/.../ffbccf5515.exe  (acffba2b2a892dc7d813ab5afb99087e)

26 / 68    (Adware)

31 / 68    (Adware)

26 / 68    (Adware)

26 / 68    (Adware)

26 / 68    (Adware)

31 / 68    (Adware)

31 / 68    (Adware)

23 / 68    (Adware)

21 / 68    (PUP)

The following 3 files have been seen to comunicate with www.adskdoom.info in live environments.

URL:
http://www.adskdoom.info/

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)