www.alamaya.me

WhoisGuard, Inc.  (Proxy Registrant)

Domain Information

The domain www.alamaya.me is registered by proxy through eNom Inc R32-ME (48) and was originally registered in September of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Registrar:
eNom Inc R32-ME (48)

Server location:
Quebec, Canada (CA)

Create date:
Monday, September 1, 2014

Expires date:
Tuesday, September 1, 2015

Updated date:
Monday, September 1, 2014

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MIDIATECHNOLOGIES.t, PUP.MIDIATECHNOLOGIES.c, PUP.MIDIATECHNOLOGIES.L, PUP.MIDIATECHNOLOGIES.m, PUP.MIDIATECHNOLOGIES.g, PUP.Midia Technologies.MIDIATECHNOLOGIES.Bundler (M), PUP.Midia Technologies.MIDIATEC.Bundler (M), PUP.Midia Technologies (M)
100.00%

avast!
Rootkit-gen [Rtk], Agent-AUDQ [Trj], Trojan-gen, Win32:Malware-gen
23.81%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
23.81%

Malwarebytes
PUP.Optional.Midia, Trojan.BHO
23.81%

Norman
Downloader
23.81%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
23.81%

Baidu Antivirus
Trojan.Win32.Generic, Adware.Win32.Midia
23.81%

Fortinet FortiGate
W32/Adload.S!tr.dldr
23.81%

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic, Trojan-Downloader.Win32.Genome
19.05%

K7 AntiVirus
Unwanted-Program
19.05%

Avira AntiVirus
TR/Agent.51080, TR/Downloader.Gen2, TR/Rogue.11819994
19.05%

ESET NOD32
NSIS/TrojanDownloader.Agent.NQD, NSIS/TrojanDownloader.Agent.NRD, NSIS/TrojanDownloader.Agent.NRF
14.29%

SUPERAntiSpyware
Trojan.Agent/Gen-FakeAlert, Trojan.Agent/Gen-Downloader
9.52%

ESET NOD32
NSIS/Agent.NBK trojan, NSIS/TrojanDownloader.Agent.NRD trojan
9.52%

AegisLab AV Signature
AdWare.MSIL.DomaIQ, Troj.Generic
9.52%

The domain www.alamaya.me has been seen to resolve to the following IP address.

onlinemidia.com
September 9, 2014

File downloads found at URLs served by www.alamaya.me.

1 / 68      (Adware)
http://www.alamaya.me/ids/.../download-video-filmes-de-sexo-sexo-em-salvador-ba.zip  (Download-video-filmes-de-sexo-sexo-em-salvador-ba.zip.exe)

1 / 68      (Adware)
http://www.alamaya.me/ids/.../MotoGP 14.exe  (2105e5b958316f9cd5fb600c090c3cc0)

1 / 68      (Adware)

1 / 68      (Adware)
http://www.alamaya.me/ids/.../download-video-filmes-de-sexo-desenho-animado-porno-gratis.zip  (download-video-filmes-de-sexo-desenho-animado-porno-gratis.zip.exe)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://www.alamaya.me/ids/.../download-video-filmes-de-sexo-pornos-com-amputados.zip  (download-video-filmes-de-sexo-pornos-com-amputados.zip.exe)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://www.alamaya.me/ids/.../download-video-filmes-de-sexo-meninas-esfregando-xoxotas-.zip  (download-video-filmes-de-sexo-meninas-esfregando-xoxotas-.zip.exe)

1 / 68      (Adware)

1 / 68      (Adware)
http://www.alamaya.me/ids/.../download-video-filmes-de-sexo-rita-cadilac-transando-.zip  (download-video-filmes-de-sexo-rita-cadilac-transando-.zip.exe)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://www.alamaya.me/ids/.../download-video-filmes-de-sexo-sexxy-clube-dos-cornos.zip  (download-video-filmes-de-sexo-sexxy-clube-dos-cornos.zip.exe)

26 / 68    (Adware)

16 / 68    (Adware)
http://www.alamaya.me/ids/.../download-video-filmes-de-sexo-oktoberfest.zip  (download-video-filmes-de-sexo-oktoberfest.zip.exe)

12 / 68    (Adware)

13 / 68    (Adware)

11 / 68    (Adware)
http://www.alamaya.me/ids/.../Download Pro Evolution Soccer 2013 PTBR Para PS2.zip  (download pro evolution soccer 2013 ptbr para ps2.zip.exe)

URL:
http://www.alamaya.me/

Web server:
nginx/1.0.15