au.fileprogram.net

Vittalia Limitted

Domain Information

The domain au.fileprogram.net registered by Vittalia Limitted was initially registered in April of 2013 through SOLUCIONES CORPORATIVAS IP,SLU. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Madrid, Madrid within Spain which resides on the RIPE Network Coordination Centre network.
Registrar:
SOLUCIONES CORPORATIVAS IP,SLU

Server location:
Madrid, Spain (ES)

Create date:
Wednesday, April 10, 2013

Expires date:
Friday, April 10, 2015

Updated date:
Tuesday, April 8, 2014

ASN:
AS45037 HISPAWEB-NETWORK Propelin Consulting S.L.U.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.InstallCore, PUP.Optional.BundleInstaller.A, PUP.Optional.DownloadAssistant, PUP.Optional.Vittalia
100.00%

VIPRE Antivirus
InstallCore.b, Threat.4782985, Threat.4782551
100.00%

Reason Heuristics
PUP.100BlogsSL.a, PUP.WorldSetup.m, PUP.Air Software, PUP.FreeSoftware
100.00%

Avira AntiVirus
Adware/InstallCore.144181, ADWARE/InstallCore.Gen7, APPL/Downloader.Gen, Adware/InstaCore.onb
100.00%

AVG
Generic_c, Trojan horse Ransomer.DBB, Adware BundleApp_r.Z
100.00%

McAfee
Artemis!D2CFE8BA58A5, Artemis!F6314EDD8478, Program.CryptVittalia
80.00%

Comodo Security
Application.Win32.InstallCore.HYE, Application.Win32.Installcore.BB, TrojWare.Win32.Agent.IEXT
80.00%

G Data
Win32.Trojan.Agent.OUXLMY, Win32.Application.InstallCore, Gen:Variant.Application.Bundler.32
80.00%

Trend Micro House Call
TROJ_GEN.F47V0428, TROJ_GEN.F47V0227
60.00%

Agnitum Outpost
PUA.InstallCore, Riskware.Agent
60.00%

Sophos
Install Core Click run software
60.00%

Vba32 AntiVirus
Downware.InstallCore
60.00%

Fortinet FortiGate
Riskware/InstallCore, Riskware/InstallCore_JE
60.00%

Qihoo 360 Security
Win32/Virus.Adware.f76, Win32/Virus.Adware.94c
60.00%

ESET NOD32
Win32/InstallCore.JE.gen potentially unwanted application, Win32/DownloadAssistant.A potentially unwanted application, Win32/Vittalia.Q potentially unwanted application
60.00%

The domain au.fileprogram.net has been seen to resolve to the following IP address.

rack6u11.hispaweb.net
April 11, 2014

File downloads found at URLs served by au.fileprogram.net.

15 / 68    (Adware)
http://au.fileprogram.net/.../download?p=AU  (installer_instagram_english.exe)

16 / 68    (Adware)

18 / 68    (Adware)
http://au.fileprogram.net/.../download?p=AU-DNM  (installer_microsoft_office_publisher_english.exe)

16 / 68    (Adware)
http://au.fileprogram.net/.../download  (f5421e82b2aa975a474b40e77fd92e67.exe)

16 / 68    (Adware)
http://au.fileprogram.net/.../download?p=AU  (afaede9e06a4f1805dc86b387049c19b.exe)

URL:
http://au.fileprogram.net/

Google Analytics:
UA-49362613

Web server:
Apache (PHP/5.3.10-1ubuntu3.9)