www.wikiupload.com

TCS

Domain Information

The domain www.wikiupload.com registered by TCS was initially registered in December of 2005 through ENOM, INC.. Currently this domain has been known to host various forms of malware. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
Arizona, United States (US)

Create date:
Monday, December 12, 2005

Expires date:
Monday, December 12, 2016

Updated date:
Tuesday, December 15, 2015

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

avast!
Win32:Evo-gen [Susp], MSIL:Agent-BXF [Trj]
100.00%

K7 AntiVirus
Riskware
50.00%

ESET NOD32
Win32/Agent.RYR
50.00%

Kaspersky
UDS:DangerousObject.Multi.Generic
50.00%

NANO AntiVirus
Trojan.Script.Agent.debxaj
50.00%

Sophos
Mal/Generic-S
50.00%

Avira AntiVirus
TR/Dropper.Gen
50.00%

AhnLab V3 Security
Trojan/Win32.HDC
50.00%

Baidu Antivirus
Trojan.Win32.Agent
50.00%

Qihoo 360 Security
HEUR/QVM06.2.Malware.Gen
50.00%

ESET NOD32
MSIL/Bladabindi.F trojan
50.00%

Dr.Web
BackDoor.Bladabindi.9336
50.00%

McAfee
Trojan.Trojan-FIGN
50.00%

Microsoft Security Essentials
Threat.Undefined
50.00%

The domain www.wikiupload.com has been seen to resolve to the following 2 IP addresses.

May 22, 2016

May 22, 2016

File downloads found at URLs served by www.wikiupload.com.

5 / 68      (Malware)

10 / 68    (Malware)
http://www.wikiupload.com/.../do_download  (tibiaautosetup_2_62_0_for_10_81.exe)

URL:
http://www.wikiupload.com/

Google Analytics:
UA-291348

Title:
“Upload Files, MP3, Music. Free File Hosting To Share Files”

Description:
“Upload files free: hosting for music, documents, mp3 and files and images. Free File Storage that is simplest and easy to use.”

SSL certificate subject:
CN=sni133413.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx (PHP/5.1.6)

Facebook:
Likes:  53
Shares:  214
Comments:  69

Statistics are for the previous month.