hawkode.com

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain hawkode.com is registered by proxy through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM and was originally registered in July of 2012. Currently this domain has been known to host various forms of malware. The hosted server (141.101.118.24) is located in Belgium which resides on the RIPE Network Coordination Centre network.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Belgium (BE)

Create date:
Wednesday, July 25, 2012

Expires date:
Friday, July 25, 2014

Updated date:
Monday, June 10, 2013

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Bkav FE
W32.Clod05a.Trojan
100.00%

McAfee
Artemis!2F6B5E0EB455
100.00%

Agnitum Outpost
Trojan.Kazy
100.00%

Norman
Troj_Generic.OQKJU
100.00%

Comodo Security
UnclassifiedMalware
100.00%

VIPRE Antivirus
Trojan.Win32.Generic
100.00%

Avira AntiVirus
TR/Dropper.MSIL.Gen
100.00%

IKARUS anti.virus
Trojan.SuspectCRC
100.00%

AVG
Dropper.Generic8
100.00%

The domain hawkode.com has been seen to resolve to the following 2 IP addresses.

April 11, 2014

April 11, 2014

File downloads found at URLs served by hawkode.com.

9 / 68      (Malware)
http://hawkode.com/.../2Famous.exe  (2f6b5e0eb45599d72cb8cf182ebdea6b)

The following 4 files have been seen to comunicate with hawkode.com in live environments.

URL:
http://hawkode.com/

Title:
“Instagram, Facebook, Tumblr, Twitter, Netlog and Twoo Bot Sotware - Download! - Hawkode”

Description:
“Hawkode provides bot software for Instagram, Facebook, Tumblr, Twitter, Netlog and Two! Check out and download our tools!”

Web server:
cloudflare-nginx (PHP/5.3.26)

Facebook:
Likes:  167
Shares:  34
Comments:  10

Statistics above are for the previous month of March 2024.