www.eimia.net

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain www.eimia.net is registered by proxy through ENOM, INC. and was originally registered in February of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Remove Malware from www.eimia.net - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
Quebec, Canada (CA)

Create date:
Thursday, February 28, 2013

Expires date:
Sunday, February 28, 2016

Updated date:
Friday, February 13, 2015

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MidiaTechnologies.F, PUP.MIDIATECHNOLOGIES.?, PUP.MIDIATECHNOLOGIES.BB, PUP.MIDIATECHNOLOGIES.i, PUP.MIDIATECHNOLOGIES.r, PUP.MIDIATECHNOLOGIES.y, PUP.MIDIATECHNOLOGIES.b, PUP.MIDIATECHNOLOGIES.CC, PUP.MIDIATECHNOLOGIES.x, PUP.MIDIATECHNOLOGIES.u, PUP.MIDIATECHNOLOGIES.AA, PUP.Midia Technologies.MIDIATECHNOLOGIES.Bundler (M), PUP.Midia Technologies.MidiaTechnologies.Bundler (M)
93.75%

AVG
Skodna.Generic
62.50%

Malwarebytes
PUP.Optional.Midia
62.50%

Baidu Antivirus
Trojan.Win32.Generic, Adware.Win32.Midia
62.50%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696
50.00%

Fortinet FortiGate
Adware/PCMega.J, W32/Adload.S!tr.dldr
43.75%

Kaspersky
not-a-virus:AdWare.Win32.AdLoad, HEUR:Trojan-Downloader.Win32.Generic
43.75%

F-Prot
W32/A-3e4ddf83, W32/S-f4ba6568, W32/A-07794f8f
37.50%

Avira AntiVirus
TR/Strictor.61091.452, TR/Dldr.Agent.71552, TR/Dldr.Agent.53408, APPL/Midia.Z
37.50%

NANO AntiVirus
Riskware.Win32.Agent.cinaww, Trojan.Win32.Strictor.deidgy, Trojan.Nsis.Downloader.dgyjkw
31.25%

Comodo Security
Application.Win32.PCMega.L
31.25%

G Data
Gen:Variant.Adware.Strictor.61091, Application.Downloader.UN, Win32.Adware.Midia
31.25%

McAfee
Artemis!CFAE1836C20E, Midia
25.00%

Rising Antivirus
PE:Malware.Downloader!1.9EEC
25.00%

Norman
Downloader
25.00%

The domain www.eimia.net has been seen to resolve to the following 4 IP addresses.

January 29, 2016

October 12, 2015

onlinemidia.com
August 26, 2014

web01.onlinemidia.com
January 14, 2014

File downloads found at URLs served by www.eimia.net.

1 / 68      (Adware)
http://www.eimia.net/ids/.../brasfoot2013build2.exe  (498a48f0717a3bcc20bec4fe3f64b4a7)

4 / 68      (inconclusive)
http://www.eimia.net/ids/id72/.../Dowload Midnight Club 3: Dub Edition 2010 Jogo Psp.zip  (dowload midnight club 3- dub edition 2010 jogo psp.zip.exe)

1 / 68      (Adware)
http://www.eimia.net/ids/.../Vizinhos 2014 Dublado.exe  (9a8b432d94248e7daeee8c483629caaa)

1 / 68      (Adware)
http://www.eimia.net/ids/.../Vizinhos 2014 Dublado.exe  (e42f553f1c6644efcae1a542cd7abbed)

11 / 68    (Adware)

12 / 68    (Adware)

18 / 68    (Adware)

18 / 68    (Adware)
http://www.eimia.net/ids/.../O Filho Do Batman Torrent Bluray 1080p Dublado 2014 .exe  (o filho do batman torrent bluray 1080p dublado 2014.exe)

17 / 68    (Adware)
http://www.eimia.net/ids/.../Uma Aventura Lego Torrent Bluray 1080p Dual Audio 2014 .exe  (uma aventura lego torrent bluray 1080p dual audio 2014.exe)

15 / 68    (Adware)

12 / 68    (Adware)

12 / 68    (Adware)
http://www.eimia.net/ids/.../Download Game Of Thrones Completo Dublado e Legendado.zip  (download game of thrones completo dublado e legendado.zip.exe)

20 / 68    (Adware)
http://www.eimia.net/ids/.../Franklin : O Tesouro do Lago da Tartaruga – Dublado.exe  (franklin - o tesouro do lago da tartaruga dublado.exe)

4 / 68      (Adware)

5 / 68      (Adware)

4 / 68      (Adware)

19 / 68    (Adware)
http://www.eimia.net/ids/.../filme.exe  (8bee79a74d23476368b3ad8f95563ca5)

The following file have been seen to comunicate with www.eimia.net in live environments.

URL:
http://www.eimia.net/

Title:
“Em manutencao”

Web server:
nginx/1.0.15 (PHP/5.6.13)

Facebook:
Shares:  1

Statistics are for the previous month.

Remove Malware from www.eimia.net - Powered by Reason Core Security