www.protectmedia.net

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain www.protectmedia.net is registered by proxy through ENOM, INC. and was originally registered in May of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Registrar:
ENOM, INC.

Server location:
Quebec, Canada (CA)

Create date:
Wednesday, May 7, 2014

Expires date:
Thursday, May 7, 2015

Updated date:
Wednesday, May 7, 2014

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.BR Software.BRSOFTWA (M), PUP.Midia Technologies.MIDIATEC.Bundler (M), PUP.MINDSTOR.Installer (M), PUP.BR Software.GENCOLAB.Installer (M), PUP.BR Software (M), PUP.Midia Technologies (M)
98.00%

MicroWorld eScan
Trojan.GenericKD.2176974
2.00%

VIPRE Antivirus
Amonetize
2.00%

Trend Micro House Call
Suspicious_GEN.F47V0219
2.00%

avast!
NSIS:Adware-RE [PUP]
2.00%

Kaspersky
Trojan-Downloader.Win32.Genome
2.00%

Bitdefender
Trojan.GenericKD.2176974
2.00%

Lavasoft Ad-Aware
Trojan.GenericKD.2176974
2.00%

Emsisoft Anti-Malware
Trojan.GenericKD.2176974
2.00%

F-Secure
Trojan.GenericKD.2176974
2.00%

Sophos
Mal/Generic-S
2.00%

Avira AntiVirus
TR/Dldr.Adload.65579
2.00%

G Data
Trojan.GenericKD.2176974
2.00%

McAfee
RDN/Generic Downloader.x!mr
2.00%

Baidu Antivirus
Adware.Win32.Genome
2.00%

The domain www.protectmedia.net has been seen to resolve to the following 2 IP addresses.

onlinemidia.com
August 1, 2014

web01.onlinemidia.com
May 31, 2014

File downloads found at URLs served by www.protectmedia.net.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
https://www.protectmedia.net/ids/.../ Norbit.exe  (771433226f211ac8e706121f09e0d68e)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

The following file have been seen to comunicate with www.protectmedia.net in live environments.

URL:
http://www.protectmedia.net/

SSL certificate subject:
CN=protectmedia.net, OU=PositiveSSL, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
nginx/1.0.15