www.protectmedia.net

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain www.protectmedia.net is registered by proxy through ENOM, INC. and was originally registered in May of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Remove Malware from www.protectmedia.net - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
Quebec, Canada (CA)

Create date:
Wednesday, May 07, 2014

Expires date:
Thursday, May 07, 2015

Updated date:
Wednesday, May 07, 2014

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.BRSOFTWARE.E, PUP.BRSOFTWARE.V, PUP.BRSOFTWARE.AA, PUP.MIDIATECHNOLOGIES.L, PUP.Midia Technologies, PUP.Installer.BR Software, PUP.BR Software.BRSOFTWARE (M), PUP.Midia Technologies.MIDIATECHNOLOGIES.Bundler (M), PUP.BR Software.GENCOLABS.Installer (M), PUP.MINDSTORM.Installer (M)
100.00%

avast!
Win32:Adware-BJA [PUP], Dropper-gen [Drp], Malware-gen, Trojan-gen, NSIS:Adware-RE [PUP]
43.75%

Kaspersky
Trojan-Banker.Win32.Lohmys, HEUR:Trojan-Downloader.Win32.Generic
43.75%

Avira AntiVirus
TR/Banker.Lohmys.a.2, TR/Downloader.Gen2, Adware/Adload.RF
43.75%

VIPRE Antivirus
Threat.4150696, Amonetize
37.50%

AVG
Skodna, Downloader.NSIS, Generic
37.50%

Malwarebytes
PUP.Optional.Midia, Trojan.BHO
31.25%

G Data
Win32.Trojan-Downloader.Agent.BP, Gen:Variant.Adware.DealPly, Trojan.Generic.12082369, Win32.Adware.Midia
31.25%

Fortinet FortiGate
W32/Fraudster.AB!tr, W32/Adload.S!tr.dldr, W32/Adload.AM!tr.dldr
31.25%

ESET NOD32
Win32/AdWare.Midia.C application, NSIS/TrojanDownloader.Agent.NRY trojan
25.00%

Baidu Antivirus
Adware.Win32.Midia
25.00%

Dr.Web
Trojan.Fraudster.1052
18.75%

Agnitum Outpost
Trojan.PWS.Lohmys
18.75%

Sophos
PCMega
18.75%

Kingsoft AntiVirus
Win32.Troj.Banker.(kcloud)
18.75%

The domain www.protectmedia.net has been seen to resolve to the following 2 IP addresses.

onlinemidia.com
August 1, 2014

web01.onlinemidia.com
May 31, 2014

File downloads found at URLs served by www.protectmedia.net.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
https://www.protectmedia.net/ids/.../100-black-vol-15.exe  (cf059a4dce7a907c227126d55b278e18)

1 / 68      (Adware)

34 / 68    (Adware)

18 / 68    (Adware)

18 / 68    (Adware)
https://www.protectmedia.net/ids/id36/.../GER).exe  (043ad6ff842f535aa2527fd54f9c9458)

The following file have been seen to comunicate with www.protectmedia.net in live environments.

URL:
http://www.protectmedia.net/

SSL certificate subject:
CN=protectmedia.net, OU=PositiveSSL, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
nginx/1.0.15

Remove Malware from www.protectmedia.net - Powered by Reason Core Security