sub2.admitlead.ru

Media, LLC

Domain Information

The domain sub2.admitlead.ru registered by Media, LLC was initially registered in April of 2014 through REGRU-RU. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Moscow, Moskva within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-RU

Server location:
Moskva, Russia (RU)

Create date:
Tuesday, April 1, 2014

Expires date:
Saturday, April 1, 2017

ASN:
AS14576 HOSTING-SOLUTIONS - Hosting Solution Ltd., US

Root domain:

Scanner detections:
Detections  (76% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MediaGet.Inbox.Installer (M), PUP.MediaGet (M), PUP.MediaSkr (M), PUP.MediaGet.Optional (L)
100.00%

Dr.Web
riskware program Program.MediaGet.142
7.69%

ESET NOD32
Win32/MediaGet.AE potentially unwanted application
7.69%

Kaspersky
not-a-virus:HEUR:Downloader.Win32.MediaGet
7.69%

Sophos
PUA 'MediaGet' (of type Hacktool)
7.69%

The domain sub2.admitlead.ru has been seen to resolve to the following 2 IP addresses.

August 30, 2016

October 24, 2014

File downloads found at URLs served by sub2.admitlead.ru.

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://sub2.admitlead.ru/sb/clk/s/1439/h/e67424/o/471/.../test?a=1&f=Highland Warriors .  (collapse-dilogiya-rus-repack-ot-rg-mehanikitorrent_id1198379ids1s.exe)

1 / 68      (PUP)

1 / 68      (PUP)
http://sub2.admitlead.ru/sb/clk/s/164/h/813b0b/o/471/.../0?a=1e  (outlast-full-turkce-indir_id2959289ids2s.exe)

1 / 68      (PUP)

1 / 68      (PUP)
http://sub2.admitlead.ru/sb/clk/s/1321/h/95a7f6/o/471/p/1507/.../0?a=1  (wolfenstein-the-old-blood-2015-pc-repack-ot-xatab_id2260452ids2s.exe)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

 
Latest 30 of 1,376 download URLs

URL:
http://sub2.admitlead.ru/

SSL certificate subject:
CN=sub2.admitlead.ru, OU=PositiveSSL, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
nginx/1.8.0 (PHP/5.5.35)