www.hakoonportal.net

c/o whoisproxy.com Ltd.

Domain Information

The domain www.hakoonportal.net registered by c/o whoisproxy.com Ltd. was initially registered in October of 2015 through KEY-SYSTEMS GMBH. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Zurich, Zurich within Switzerland which resides on the RIPE Network Coordination Centre network.
Registrar:
KEY-SYSTEMS GMBH

Server location:
Zurich, Switzerland (CH)

Create date:
Thursday, October 1, 2015

Expires date:
Saturday, October 1, 2016

Updated date:
Wednesday, November 11, 2015

ASN:
AS40034 CONFLUENCE-NETWORK-INC - Confluence Networks Inc,VG

Root domain:

Scanner detections:
Detections  (91% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.VisualTools.G, PUP.gooternet.J, Threat.Win.Reputation.IMP, PUP.Installer.Jambo, PUP.Resoft.MYPOPSHOP, PUP.LiyanLiu.J, PUP.LiMo.J, PUP.Midia Technologies.MIDIATECHNOLOGIES.Bundler (M), PUP.Midia Technologies.MIDIATEC.Bundler (M)
90.91%

Trend Micro House Call
TROJ_GEN.F47V1105, Suspicious_GEN.F47V0615, Suspicious_GEN.F47V0611, TROJ_GEN.R0C1H09HT14, Suspicious_GEN.F47V0722, Suspicious_GEN.F47V0731
54.55%

McAfee
Artemis!4EE888A69EFB, Artemis!4B60FC2593E8, Artemis!C523AC284CBD, Artemis!157990057455, Downloader-FAGU!4E3FA8A86D87, Artemis!6F67E1B655F1, Artemis!6D3CFEEBF716
36.36%

ESET NOD32
Win32/Toolbar.Babylon (variant), Win32/BrowseFox, Win32/AdWare.PennyBee (variant), MSIL/Toolbar.Linkury (variant), Win32/ELEX.AT (variant)
31.82%

Dr.Web
Trojan.BPlug.100, Trojan.Lyrics.150, Adware.Mutabaha.67, Trojan.Inject1.43330, Tool.NetFilter.1, Adware.Linkury.10, Adware.Mutabaha.70
31.82%

Malwarebytes
PUP.Optional.Babylon, PUP.Optional.PennyBee.A, PUP.Optional.SearchHijacker.A
22.73%

Sophos
Mal/FakeAV-OY, Generic PUA IA, Generic PUA MP, Generic PUA LF, PennyBee
22.73%

VIPRE Antivirus
Babylon, Threat.4150696, Trojan.Win32.Generic
22.73%

Qihoo 360 Security
HEUR/Malware.QVM06.Gen, Win32/Virus.Adware.eb2, Win32/Trojan.67a, Trojan.Generic
22.73%

G Data
Gen:Variant.Graftor.153165, Trojan.GenericKD.1869073, Win32.Application.Linkury, Win32.Adware.Adpeak
22.73%

NANO AntiVirus
Riskware.Win32.Babylon.craswq, Trojan.Win32.Lyrics.ddtbvt, Riskware.Win32.Linkury.dcvwxz
18.18%

AVG
Generic, Generic5, Mypopshop
18.18%

Agnitum Outpost
PUA.PennyBee, Riskware.Agent, PUA.Toolbar.Linkury, PUA.Mutabaha
18.18%

AhnLab V3 Security
PUP/Win32.Pennybee, PUP/Win32.Downloader, PUP/Win32.Dropper
18.18%

K7 AntiVirus
Trojan , Adware , Unwanted-Program
13.64%

The domain www.hakoonportal.net has been seen to resolve to the following IP address.

February 7, 2016

File downloads found at URLs served by www.hakoonportal.net.

13 / 68    (Adware)
http://www.hakoonportal.net/.../310714_a5.exe  (3905ec00f3f91bc0d17e6d221e2de44a)

1 / 68      (Adware)
http://www.hakoonportal.net/.../310714_o.exe  (46c654b981b3086373b2b8f6a52d5fb8)

1 / 68      (Adware)
http://www.hakoonportal.net/.../220814_m.exe  (0f8f641c1a6e33757d92cead4f2cc9fd)

4 / 68      (inconclusive)
http://www.hakoonportal.net/.../310714_f4.exe  (1ba0bad337dc0386c20c1316559e0167)

20 / 68    (Adware)
http://www.hakoonportal.net/.../310714_y2.exe  (157990057455220096968a6cf991a87e)

1 / 68      (Adware)
http://www.hakoonportal.net/.../220814_m.exe  (13a0b04dd9c130d0a33276a2b2630372)

1 / 68      (Adware)
http://www.hakoonportal.net/.../310714_o.exe  (6b011c14647c04d25445ed02804eaefb)

1 / 68      (Adware)
http://www.hakoonportal.net/.../220814_m.exe  (ca9fc42a61cdefe49424a27f7684c325)

11 / 68    (Adware)

1 / 68      (Adware)
http://www.hakoonportal.net/.../310714_o.exe  (874581359051e1354d95387485dcf5b2)

1 / 68      (Adware)
http://www.hakoonportal.net/.../220814_m.exe  (fd87e4969c2b3860b7e5bc9bed65b9df)

8 / 68      (Adware)
http://www.hakoonportal.net/.../310714_a6.exe  (33726375be3339402d859c22d36221ac)

11 / 68    (Adware)

9 / 68      (Malware)

22 / 68    (Adware)

7 / 68      (Adware)
http://www.hakoonportal.net/.../310714_a6.exe  (6d3cfeebf7165504b5b8dff3a2802113)

7 / 68      (Adware)
http://www.hakoonportal.net/.../310714_b.exe  (0672a4f0bc8c928598abd09487515906)

11 / 68    (Adware)

1 / 68      (Adware)
http://www.hakoonportal.net/.../310714_o.exe  (00ca3412a58642b32e2780ba31777eb6)

1 / 68      (Adware)
http://www.hakoonportal.net/.../220814_m.exe  (26db846cd63c42677aabf0ebebd99820)

3 / 68      (Adware)
http://www.hakoonportal.net/.../310714_l.exe  (9c513c3e531ab77b5082aec19164b48c)

22 / 68    (Adware)

11 / 68    (Adware)

URL:
http://www.hakoonportal.net/

Title:
“hakoonportal.net”

Web server:
Apache