apps.foxtab.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain apps.foxtab.com is registered by proxy through GODADDY.COM, LLC and was originally registered in September of 2008. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Saturday, September 06, 2008

Expires date:
Friday, September 06, 2019

Updated date:
Sunday, January 05, 2014

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.InstallCore.J, PUP.Installer.IronSource.P, PUP.Installer.InstallCore.T, PUP.Installer.InstallCoreCTechnologies.J, PUP.Installer.InstallCore.O, PUP.Installer.ADLSoft.O, PUP.ironSource.Installer (M), PUP.ironSource.AVIConverterTechnologie.Installer (M), PUP.installCore.MusicConverterT.Installer (M), PUP.installCore.VideoConverterTechnologies.Installer (M), PUP.installCore.VideoToMP3Tech.Installer (M), PUP.installCore.ClickRunSoftware.Installer (M), Threat.Win.Reputation.IMP, PUP.installCore.FLVPlayerTechnologies.Installer (M), PUP.installCore.VideoToMP3Technologies.Installer (M), PUP.installCore.AVIConverterTec.Installer (M), PUP.installCore.PDFConverterTechnologies.Installer (M), PUP.installCore.Installer (M), PUP.installCore.CoolAppDownloads.Installer (M), PUP.installCore.MP3Conve.Installer (M), PUP.installCore.FLVPlaye.Installer (M), PUP.installCore.Coolappt.Installer (M), PUP.installCore (M)
91.84%

Avira AntiVirus
ADWARE/InstallCore.Gen, ADWARE/InstallCore.Gen9, Adware/Facemoods.C, ADWARE/Adware.Gen, PUA/InstallCore.Gen, ADWARE/InstCore.368
61.22%

ESET NOD32
Win32/InstallCore (variant), Win32/SweetIM (variant), Win32/InstallCore.JW (variant), Win32/InstallCore.Gen, Win32/InstallCore.D potentially unwanted (variant)
61.22%

Malwarebytes
Adware.Agent, PUP.Adware.InstallCore, PUP.Optional.InstallCore.A, Affiliate.Downloader
59.18%

Sophos
Install Core Installer, Troj/Agent-TTL, Install Core Click run software, Install Core Installer (PUA)
59.18%

VIPRE Antivirus
InstallCore, Trojan.Win32.Generic, InstallCore.b
59.18%

F-Prot
W32/InstallCore.A.gen, W32/InstallCore.I.gen, W32/Agent.MC.gen, W32/InstallCore.A2.gen
57.14%

Dr.Web
Adware.InstallCore.14, Adware.InstallCore.39, Adware.InstallCore.13, Trojan.DownLoader2.12839, Adware.Zugo.37, Trojan.DownLoader2.12660
57.14%

Comodo Security
ApplicUnwnt.Win32.AdWare.InstallCore.0, ApplicUnwnt.Win32.AdWare.InstallCore.1, Heur.Suspicious, TrojWare.Win32.Agent.cczj
48.98%

Baidu Antivirus
Trojan.Win32.Agent, Adware.Win32.InstallCore, Trojan.Win32.SweetIM
44.90%

Rising Antivirus
AdWare.Win32.InstallCore.b, PE:Malware.Graftor!6.870, PE:Trojan.Win32.Generic.1526E028!354869288, PE:PUF.InstallCore!1.9DE1
44.90%

K7 AntiVirus
Trojan, Unwanted-Program , Trojan , Riskware, Riskware
42.86%

K7 Gateway Antivirus
Trojan, Unwanted-Program , Trojan , Riskware , Adware
42.86%

avast!
Win32:InstallCore-F [PUP], Win32:InstallCore-HF [PUP], Win32:InstallCore-BA [PUP], Win32:Trojan-gen, Win32:PUP-gen [PUP]
42.86%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious-BAY.G, Heuristic.BehavesLike.Win32.Suspicious-BAY.K, Heuristic.BehavesLike.Win32.Suspicious-PKR.G
42.86%

The domain apps.foxtab.com has been seen to resolve to the following 3 IP addresses.

ec2-107-21-94-174.compute-1.amazonaws.com
January 8, 2014

ec2-107-21-215-95.compute-1.amazonaws.com
January 8, 2014

ec2-23-23-97-79.compute-1.amazonaws.com
January 8, 2014

File downloads found at URLs served by apps.foxtab.com.

1 / 68      (Adware)
http://apps.foxtab.com/RC/.../FlvPlayerSetup.exe  (f17425223b940443b6da64a1c48dbacd)

1 / 68      (Adware)
http://apps.foxtab.com/RC/.../AVIConverterSetup.exe  (84f981d49faf326b1a2fc65fd942f020)

1 / 68      (Adware)
http://apps.foxtab.com/RC/.../FlvPlayerSetup.exe  (97a0612d3ae667cfef8386c529e162ec)

30 / 68    (PUP)
http://apps.foxtab.com/.../FLVPlayerSetup.exe  (67352ad6c21bdb592369005946a1cd12)

41 / 68    (Adware)

28 / 68    (Adware)

29 / 68    (Adware)
http://apps.foxtab.com/RC/.../VideoConverterSetup.exe  (987d9ea4518e7db4339f1979a6f14ae2)

35 / 68    (Adware)

1 / 68      (Malware)
http://apps.foxtab.com/.../VideoToMp3Setup.exe  (4e49693e1b30f3528b1132045ae74e14)

25 / 68    (Adware)

28 / 68    (PUP)
http://apps.foxtab.com/.../VideoConverterSetup.exe  (aaee32f56d6f31caf33e38114954f26d)

1 / 68      (Adware)

1 / 68      (Adware)
http://apps.foxtab.com/.../MP3ConverterSetup.exe  (aeba707768c559084e31eb90c06abb53)

1 / 68      (Adware)
http://apps.foxtab.com/RC/.../VideoToMP3Setup.exe  (7ff3fa6abc972e6ee6ba918d056aa88b)

37 / 68    (Adware)

15 / 68    (Adware)

1 / 68      (Adware)
http://apps.foxtab.com/.../FLVPlayerSetup.exe  (cd9f1ad0b6c6f34cce862b58e31dd47a)

1 / 68      (Adware)
http://apps.foxtab.com/.../PDFConverterSetup.exe  (759a3e1d3b0aa72ec66059c1af609d7f)

15 / 68    (Adware)

1 / 68      (Adware)
http://apps.foxtab.com/.../MusicConverterSetup.exe  (59c90f8b15f289d5d3b7c4a78d1492ba)

30 / 68    (Adware)
http://apps.foxtab.com/RC/.../VideoConverterSetup.exe  (1f2706b8211fff0ff5e8a7c7c5b7e36b)

22 / 68    (Adware)
http://apps.foxtab.com/prod/.../VideoToMp3Setup.exe  (22d18a6ce31a7479f5bac0180bfde6ce)

24 / 68    (PUP)
http://apps.foxtab.com/RC//.../VideoConverterSetup.exe  (45b869b355451b3ef37f4eb8a4347d0b)

16 / 68    (Adware)
http://apps.foxtab.com/.../PDFConverterSetup.exe  (2c371fae5575b4365c1aa0f17273076d)

URL:
http://apps.foxtab.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Microsoft-IIS/7.0

Compete.com:
US visitors:  1,007

Statistics are for the previous month.