magiccare.net

DivineMedia Inc

Domain Information

The domain magiccare.net registered by DivineMedia Inc was initially registered in August of 2013 through MEGAZONE CORP. DBA HOSTING.KR. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Seoul, Seoul-T'Ukpyolsi within Korea which resides on the Asia Pacific Network Information Centre network.
Registrar:
MEGAZONE CORP. DBA HOSTING.KR

Server location:
Seoul-T'Ukpyolsi, Korea (KR)

Create date:
Wednesday, August 21, 2013

Expires date:
Sunday, August 21, 2016

Updated date:
Saturday, November 28, 2015

ASN:
AS3786 LGDACOM LG DACOM Corporation, KR

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Service.DivineMedia.F, PUP.DivineMedia (M), PUP.DivineMe (M)
100.00%

MicroWorld eScan
Gen:Variant.Graftor.123565
25.00%

McAfee
Artemis!B3408AC4DCE8
25.00%

Trend Micro House Call
TROJ_GEN.F47V1221
25.00%

avast!
Win32:Adware-AZC [Adw]
25.00%

Bitdefender
Gen:Variant.Graftor.123565
25.00%

Lavasoft Ad-Aware
Gen:Variant.Graftor.123565
25.00%

Comodo Security
ApplicUnwnt
25.00%

F-Secure
Gen:Variant.Graftor.123565
25.00%

VIPRE Antivirus
Trojan.Win32.Generic
25.00%

Emsisoft Anti-Malware
Gen:Variant.Graftor.123565
25.00%

G Data
Gen:Variant.Graftor.123565
25.00%

ESET NOD32
Win32/AdWare.Kraddare.IP (variant)
25.00%

IKARUS anti.virus
Win32.SuspectCrc
25.00%

Fortinet FortiGate
Riskware/Kraddare
25.00%

The domain magiccare.net has been seen to resolve to the following IP address.

couponbaby.co.kr
May 26, 2016

File downloads found at URLs served by magiccare.net.

1 / 68      (Adware)
http://magiccare.net/ver3/app/.../mcse.exe  (148a16c03e79f9de148ebca63ca2f380)

1 / 68      (Adware)
http://magiccare.net/ver3/app/.../synth.exe  (db07c2ab476fc60913367830261233f4)

17 / 68    (Adware)
http://magiccare.net/ver3/app/.../mcsvr.exe  (b3408ac4dce87ecfec459a63653333a5)

1 / 68      (Adware)
http://magiccare.net/ver3/app/.../mcsctr.exe  (88df6b0b2017d4a88d40c99540125274)

The following file have been seen to comunicate with magiccare.net in live environments.

URL:
http://magiccare.net/

Title:
“ɾ”

Web server:
Apache (PHP/5.2.17)