638.reimsrvcm.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain 638.reimsrvcm.com is registered by proxy through GODADDY.COM, LLC and was originally registered in April of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Voxel Dot Net, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
New York, United States (US)

Create date:
Sunday, April 17, 2016

Expires date:
Tuesday, April 17, 2018

Updated date:
Sunday, April 17, 2016

ASN:
AS29791 VOXEL-DOT-NET - Voxel Dot Net, Inc., US

Root domain:

Scanner detections:
Detections  (86% detected)

Scan engine
Details
Detections

Reason Heuristics
Win32.Generic.Reimage.Installer.Meta, PUP.Reimage.ReimageR.Installer.Meta (L), PUP.Reimage.Installer.Meta (L)
85.71%

Dr.Web
Program.Unwanted.493, riskware program Program.Unwanted.929, riskware program Program.Unwanted.1470
57.14%

Bkav FE
W32.HfsAdware
14.29%

ESET NOD32
Win32/ReImageRepair.F potentially unwanted
14.29%

Clam AntiVirus
Win.Trojan.Slugin-260
14.29%

McAfee
Artemis!D7830F8B35ED
14.29%

Baidu Antivirus
PUA.Win32.ReImageRepair
14.29%

Fortinet FortiGate
Riskware/ReImageRepair
14.29%

Malwarebytes
PUP.Optional.ReImageRepair.A
14.29%

Trend Micro House Call
Suspicious_GEN.F47V0520
14.29%

Rising Antivirus
Trojan.Kryptik!8.8-9rKczpjB2DO (Cloud)
14.29%

The domain 638.reimsrvcm.com has been seen to resolve to the following 2 IP addresses.

June 5, 2016

June 5, 2016

File downloads found at URLs served by 638.reimsrvcm.com.

URL:
http://638.reimsrvcm.com/

Web server:
nginx/1.9.12