update.bmmedia.net

LLC Lega media

Domain Information

The domain update.bmmedia.net registered by LLC Lega media was initially registered in April of 2013 through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Wednesday, April 17, 2013

Expires date:
Wednesday, April 17, 2019

Updated date:
Monday, April 14, 2014

ASN:
AS35415 WEBZILLA Webzilla B.V.,NL

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.OOOLegaMedia.I, PUP.Installer.OOOLegaMedia.M, PUP.OOOLegaMedia.Installer (M), PUP.OOOLegaM.Installer (M)
88.89%

Dr.Web
Tool.DownLoader.61, Trojan.Skymoner.2, Adware.Downware.2095
66.67%

Avira AntiVirus
TR/Crypt.EPACK.Gen2, APPL/BmMedia.E.1
22.22%

Clam AntiVirus
Win.Trojan.Generickd-368
11.11%

ESET NOD32
Win32/bmMedia
11.11%

Bkav FE
W32.HfsAdware
11.11%

Trend Micro House Call
Suspici.6C64B4AC
11.11%

NANO AntiVirus
Riskware.Nsis.Adware.dqadiu
11.11%

The domain update.bmmedia.net has been seen to resolve to the following IP address.

March 3, 2016

File downloads found at URLs served by update.bmmedia.net.

1 / 68      (Adware)

2 / 68      (Adware)
http://update.bmmedia.net/bmsetup.exe  (df06e05fbffbb7b92a44e4adb362c7e6)

1 / 68      (Adware)

6 / 68      (Adware)

4 / 68      (Adware)

2 / 68      (Adware)

2 / 68      (Adware)
http://update.bmmedia.net/.../bmsetup_ybru.exe  (290745366d98818535c89ee2992c5b46)

2 / 68      (Adware)

1 / 68      (Adware)

The following 3 files have been seen to comunicate with update.bmmedia.net in live environments.

URL:
http://update.bmmedia.net/

Web server:
nginx