www.kiemthe99.com

WhoisGuard, Inc.  (Proxy Registrant)

Domain Information

The domain www.kiemthe99.com is registered by proxy through ENOM, INC. and was originally registered in April of 2013. Currently this domain has been known to host various forms of malware. The hosted servers are located in Singapore, Singapore within Singapore which resides on the Asia Pacific Network Information Centre network.
Registrar:
ENOM, INC.

Server location:
Singapore, Singapore (SG)

Create date:
Thursday, April 11, 2013

Expires date:
Friday, April 11, 2014

Updated date:
Thursday, April 11, 2013

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

K7 AntiVirus
Riskware
100.00%

Norman
Troj_Generic.MRVFB
100.00%

ESET NOD32
Win32/Packed.Autoit
100.00%

Trend Micro House Call
TROJ_GEN.F0C2C0KGS13
100.00%

avast!
AutoIt:QHost-F [Trj]
100.00%

Kaspersky
Trojan.Win32.Qhost
100.00%

Sophos
Mal/Generic-S
100.00%

Comodo Security
UnclassifiedMalware
100.00%

Avira AntiVirus
TR/Malagent.A.5285
100.00%

Trend Micro
TROJ_GEN.F0C2C0KGS13
100.00%

Microsoft Security Essentials
Trojan:Win32/Malagent
100.00%

Vba32 AntiVirus
Trojan.Autoit.F
100.00%

Fortinet FortiGate
W32/Qhost.AFZO!tr
100.00%

Panda Antivirus
Trj/CI.A
100.00%

Bkav FE
HW32.CDB
100.00%

The domain www.kiemthe99.com has been seen to resolve to the following IP address.

sg2nlhg266c1266.shr.prod.sin2.secureserver.net
August 24, 2013

File downloads found at URLs served by www.kiemthe99.com.

26 / 68    (Malware)
http://www.kiemthe99.com/.../update.exe  (6c251226a83e4b6f95d80388e1b65510)

The following 3 files have been seen to comunicate with www.kiemthe99.com in live environments.

Facebook:
Likes:  3
Shares:  2
Comments:  5

Statistics are for the previous month.