www.searchapps.me

Whois Privacy (enumDNS dba)

Domain Information

Currently this domain has been known to host various forms of malware. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
EuroDNS S.A.

Server location:
Arizona, United States (US)

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC

Root domain:

Scanner detections:
Malware distribution  (83% detected)

Scan engine
Details
Detections

Reason Heuristics
(M), PUP.Bundler, PUP.Win.Reputation, Adware.Bundler (M), PUP.InstallCore.Internet.Installer.Meta (M), Adware.DownloadShield.Bundle.Meta (M), PUP.NOSIBAY.Installer, Adware.DownloadShield.Bundle (M)
67.50%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, Worm.Koobface
52.50%

McAfee Web Gateway
BehavesLike.Win32.Downloader.ch, BehavesLike.Win32.StartPage.ch, RDN/Generic Downloader.x!np, BehavesLike.Win32.Dropper.nc
25.00%

Trend Micro House Call
TROJ_GEN.F47V0803, HV_ZYX_CA083374.TOMC, ADW_OPENCANDY, Suspicious_GEN.F47V0904, TROJ_GEN.F47V0306, TROJ_GEN.R0EBH06EQ15, Suspicious_GEN.F47V1110, TROJ_GEN.F47V0425
22.50%

avast!
Win32:Rootkit-gen [Rtk], Win32:Malware-gen
20.00%

AVG
MultiBundle, Skodna.Bundle_c, Could be an adware MultiBundle
20.00%

SUPERAntiSpyware
Heur.Agent/Gen-WhiteBox, Trojan.Agent/Gen-Downloader
17.50%

NANO AntiVirus
Trojan.Win32.BrowseBan.cvsxvp, Trojan.Win32.StartPage.dbicfr, Riskware.Nsis.Adware.dpyapb, Riskware.Nsis.Dloader.dvvnkj
17.50%

McAfee
RDN/Generic Downloader.x!np, Artemis!04B3FD7F0227, RDN/Generic StartPage!by, Artemis!76583B6B29F4, Artemis!98B14C81A658
15.00%

Dr.Web
Adware.Downware.8442, Trojan.DownLoader13.18115, Trojan.MulDrop5.15116, Trojan.DownLoader15.35828, Trojan.DownLoader15.61998
12.50%

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra, Conduit
12.50%

Malwarebytes
PUP.Adware.Agent, Trojan.Downware, PUP.Optional.BundleInstaller
10.00%

Antiy Labs AVL
Trojan[:HEUR]/Win32.AGeneric, Trojan/win32.agent.gen, Trojan[:HEUR]/Win32.Unknown
7.50%

Baidu Antivirus
Trojan.Win32.StartPage, PUA.Win32.SearchApps, PUA.Win32.DownWare
7.50%

IKARUS anti.virus
AdWare.MultiBundle, Net-Worm.Win32.Koobface
7.50%

The domain www.searchapps.me has been seen to resolve to the following 3 IP addresses.

May 4, 2015

May 4, 2015

p3nlhg386c1386.shr.prod.phx3.secureserver.net
January 24, 2014

File downloads found at URLs served by www.searchapps.me.

0 / 68
http://www.searchapps.me/.../Flash_Player.exe  (73f103fb30722ac5d3541f5021f77ddd)

1 / 68      (PUP)

5 / 68      (PUP)
http://www.searchapps.me/.../download.php  (adobe_flash_player.exe)

1 / 68      (PUP)

8 / 68      (Malware)

0 / 68
http://www.searchapps.me/lp/.../Flash_Player.exe  (375016adeb6f44f71b5ab95a4b5a504f)

0 / 68
http://www.searchapps.me/.../speed.exe  (9a94029ef32f5a81b30584bc39bc4234)

0 / 68
http://www.searchapps.me/.../PDF_Reader_Setup.exe  (1cda2292960912eb5f8d06d564250ff7)

3 / 68

1 / 68      (PUP)

1 / 68
http://www.searchapps.me/.../Gimp.exe  (92d4b0fd96b306e198641aad7fcf3e03)

2 / 68      (Malware)
http://www.searchapps.me/.../PDF_Reader.exe  (e6176ae9221a15999798d8bb58d63d31)

2 / 68      (Malware)

1 / 68      (PUP)

3 / 68      (PUP)

1 / 68      (Malware)
http://www.searchapps.me/Simutrans.zip  (472bbd0e2cc1e38dd302d5d66edd915a)

0 / 68
http://www.searchapps.me/.../download.php  (gimp-2.6.11-i686-setup-1.exe)

2 / 68      (Malware)

7 / 68      (Malware)

1 / 68      (Malware)
http://www.searchapps.me/download/.../PDF_Reader.exe  (e25711776412a032b5b9f05269eadc77)

3 / 68      (Malware)
http://www.searchapps.me/download/.../PDF_Reader.exe  (3305a74e10fc746907441616ad8c8728)

The following file have been seen to comunicate with www.searchapps.me in live environments.

URL:
http://www.searchapps.me/

Title:
“SearchApps”

SSL certificate subject:
CN=sni55794.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx

Facebook:
Shares:  2

Statistics are for the previous month.