xdisc.biz

WhoisGuard, Inc.  (Proxy Registrant)

Domain Information

The domain xdisc.biz is registered by proxy through ENOM, INC. and was originally registered in October of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in London, England within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
England, United Kingdom (GB)

Create date:
Wednesday, October 23, 2013

Expires date:
Saturday, October 22, 2016

Updated date:
Monday, February 8, 2016

ASN:
AS15830 TELECITY-LON TELECITYGROUP INTERNATIONAL LIMITED,GB

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.KOMPANIYAR.i, PUP.Installer.Wilmaonline.AA, PUP.Installer.Wilmaonline.f, PUP.Installer.Wilmaonline.BB, PUP.Installer.Wilmaonline.k, Threat.Win.Reputation.IMP, PUP.Brightcircle.Wilmaonline.Bundler (M), PUP.Adknowledge.InstallM.Installer (M), Adware.Amonetize.Installer.Meta (M), PUP.Amonetize.ShetefSo.Bundler (M), PUP.Brightcircle.Wilmaonl.Bundler (M), PUP.Amonetize.Bundler, PUP.Amonetize.InstallP.Installer (M), PUP.Amonetize.Bundler (M), PUP.Adknowledge (M), PUP.Brightcircle (M)
97.96%

AVG
Generic, Generic_r
24.49%

ESET NOD32
Win32/Amonetize.BI (variant), Win32/Amonetize.BM (variant), Win32/Amonetize.BK (variant), Win32/Amonetize.BN (variant), Win32/Amonetize.BG (variant)
24.49%

Baidu Antivirus
Adware.Win32.Amonetize
22.45%

Malwarebytes
PUP.Optional.Downloader, PUP.Optional.Amonetize
22.45%

Dr.Web
Adware.Downware.5913, Adware.Downware.8012, Adware.Downware.8379, Adware.Downware.5717, Adware.Downware.7833, Adware.Downware.2250
22.45%

AhnLab V3 Security
PUP/Win32.Amonetiz, PUP/Win32.Amonetize
22.45%

G Data
Win32.Application.Amonetize, Gen:Variant.Application.Bundler.Amonetize.12, Gen:Variant.Application.Bundler.Amonetize.11
20.41%

McAfee
Artemis!3CCC98A653AD, Artemis!561440428413, Artemis!21F0E588CB01, Artemis!2C0701E0C656, PUP-Amonetize, Artemis!AE6013DBBAB9, Artemis!1C6767A15581
20.41%

NANO AntiVirus
Riskware.Win32.Amonetize.dchxoa, Riskware.Win32.Amonetize.ddtnan, Riskware.Win32.Amonetize.ddslgj, Riskware.Win32.Amonetize.dcckkw
18.37%

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
18.37%

Sophos
Generic PUA MC, Generic PUA FF, Generic PUA ED, Generic PUA HD, Generic PUA HN, Generic PUA MD, Amonetize, Virus 'Mal/HckPk-A'
18.37%

MicroWorld eScan
Application.Bundler.Amonetize.N, Gen:Variant.Application.Bundler.Amonetize.12, Gen:Variant.Application.Bundler.Amonetize.11, Trojan.GenericKD.1761950, Gen:Variant.Application.Bundler.Amonetize.14
16.33%

Trend Micro House Call
Suspicious_GEN.F47V0717, Suspicious_GEN.F47V0810, Suspicious_GEN.F47V0814, TROJ_GEN.F0C2H00GM14, Suspicious_GEN.F47V0713
16.33%

Bitdefender
Application.Bundler.Amonetize.N, Gen:Variant.Application.Bundler.Amonetize.12, Gen:Variant.Application.Bundler.Amonetize.11
16.33%

The domain xdisc.biz has been seen to resolve to the following 6 IP addresses.

163-172-16-245.rev.poneytelecom.eu
February 10, 2016

li463-168.members.linode.com
May 5, 2015

July 23, 2014

July 23, 2014

July 10, 2014

July 10, 2014

File downloads found at URLs served by xdisc.biz.

15 / 68    (Adware)
http://xdisc.biz/tracking202/.../dl.php?t202id=7583&c1=20385943561404209299&c2=null&t202kw=787 POP 125524  (microsoft.project.professional.2010.with.sp1 zwtiso__3515_i979994463_il1609123.exe)

1 / 68      (Adware)

 
Latest 30 of 87 download URLs

The following file have been seen to comunicate with xdisc.biz in live environments.

December 1, 2014

July 10, 2014

URL:
http://xdisc.biz/

Web server:
nginx/1.8.0