cached.dataurls.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain cached.dataurls.com is registered by proxy through ENOM, INC. and was originally registered in March of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada.
Registrar:
ENOM, INC.

Server location:
Quebec, Canada (CA)

Create date:
Saturday, March 14, 2015

Expires date:
Monday, March 14, 2016

Updated date:
Thursday, December 17, 2015

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.iMedia.IMediaHoldings.Installer (M), PUP.iMedia.IMediaHo.Installer (M)
100.00%

Malwarebytes
PUP.Optional.PrxySvrRST
57.14%

K7 AntiVirus
Adware
57.14%

ESET NOD32
Win32/Adware.Salus.E.Gen
57.14%

avast!
NSIS:Adware-RD [Adw]
57.14%

Dr.Web
Adware.Salus.11
57.14%

AhnLab V3 Security
Win-PUP/Salus, PUP/Win32.Salus
57.14%

AVG
Generic
57.14%

Bkav FE
W32.HfsAdware
42.86%

VIPRE Antivirus
NetFilter
14.29%

The domain cached.dataurls.com has been seen to resolve to the following 4 IP addresses.

June 7, 2016

May 24, 2016

May 18, 2016

May 16, 2016

File downloads found at URLs served by cached.dataurls.com.

9 / 68      (Adware)

1 / 68      (Adware)
http://cached.dataurls.com/si6vt20dfg25.exe  (f35e4a2d96a3c649a4e5061b21966e3a)

9 / 68      (Adware)

9 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

9 / 68      (Adware)

The following file have been seen to comunicate with cached.dataurls.com in live environments.