down.signkey.co.kr

Domain Information

Server location:
Seoul-T'Ukpyolsi, Korea (KR)

ASN:
AS3786 LGDACOM LG DACOM Corporation,KR

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

McAfee
Artemis!64A9B172594F, Artemis!0D66A0BE2546, Trojan.Artemis!A3DA27A6AE2C, Trojan.GenericR-CCI!FC6D0C7A301A
57.14%

avast!
Win32:Adware-BCF [Adw], Win32:Adware-gen [Adw], Downloader-RJH [Trj]
57.14%

Reason Heuristics
PUP.JAMIcommunication.E, PUP.LEEYEONc (M)
57.14%

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.54090, Gen:Variant.Adware.Graftor.121971
42.86%

Bkav FE
W32.Clod26b.Trojan, W32.HfsAdware
28.57%

K7 AntiVirus
Riskware , Trojan
28.57%

Agnitum Outpost
Trojan.Graftor, PUA.Kraddare
28.57%

Sophos
Generic PUA EL, Generic PUA AN (PUA)
28.57%

Avira AntiVirus
TR/Graftor.109906.20, ADWARE/Symmi.36013.37
28.57%

AhnLab V3 Security
PUP/Win32.SignKey
28.57%

ESET NOD32
Win32/Adware.Kraddare.HH (variant), Win32/AdWare.Kraddare.JP (variant)
28.57%

IKARUS anti.virus
Win32.SuspectCrc
28.57%

AVG
Generic5
28.57%

ESET NOD32
Win32/AdWare.Kraddare.JF application
28.57%

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.121971
28.57%

The domain down.signkey.co.kr has been seen to resolve to the following 2 IP addresses.

February 6, 2016

February 6, 2016

File downloads found at URLs served by down.signkey.co.kr.

1 / 68      (Adware)
http://down.signkey.co.kr/star/.../signkey.exe  (6086ee3ff2b2780d910f61ae14a2aa08)

1 / 68      (Adware)
http://down.signkey.co.kr/.../b_signkeyex.exe  (d365d2aea2fe661ee3f9ea50c8cbb4c1)

1 / 68      (Adware)
http://down.signkey.co.kr/.../signkey.exe  (ec962f0e76e7db4c8de5a2f9bcd54a82)

7 / 68      (PUP)
http://down.signkey.co.kr/.../signkey.exe  (a3da27a6ae2c88e4415bbe859b5b0223)

17 / 68    (PUP)
http://down.signkey.co.kr/.../skun.exe  (64a9b172594f2cc9837ba0d83e839c17)

6 / 68      (PUP)
http://down.signkey.co.kr/star/.../signkey.exe  (325726df1f2772a6710d4839561487e5)

28 / 68    (PUP)
http://down.signkey.co.kr/.../a_signkeyex.exe  (0d66a0be2546c02722746d1d4d894dcb)