d.unfriendtool.com

Corp New Ventures Services

Domain Information

The domain d.unfriendtool.com registered by Corp New Ventures Services was initially registered in July of 2014 through EUTURBO.COM LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Road Town, British Virgin Islands within VG which resides on the Confluence Networks Inc network.
Registrar:
EUTURBO.COM LLC

Server location:
British Virgin Islands, VG (VG)

Create date:
Friday, July 25, 2014

Expires date:
Monday, July 25, 2016

Updated date:
Tuesday, September 22, 2015

ASN:
AS40034 CONFLUENCE-NETWORK-INC - Confluence Networks Inc,VG

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.CloudCanvas.Installer (M)
100.00%

Malwarebytes
PUP.Optional.Conduit.A
33.33%

NANO AntiVirus
Riskware.Win32.Conduit.dgiaiz
33.33%

avast!
Win32:BHO-AMO [PUP]
33.33%

Comodo Security
Application.Win32.ExFriendAlert.B
33.33%

Dr.Web
Adware.Plugin.36
33.33%

VIPRE Antivirus
Conduit
33.33%

G Data
Win32.Adware.Conduit
33.33%

McAfee
Artemis!2CF5D5BD7A84
33.33%

ESET NOD32
Win32/ExFriendAlert
33.33%

IKARUS anti.virus
PUA.ExFriendAlert
33.33%

The domain d.unfriendtool.com has been seen to resolve to the following IP address.

December 23, 2015

File downloads found at URLs served by d.unfriendtool.com.

1 / 68      (Adware)
http://d.unfriendtool.com/UnfriendTool/456/.../Setup.exe  (9e3df3601be2ea096b991808987dd760)

11 / 68    (Adware)
http://d.unfriendtool.com/UnfriendTool/457/.../Setup.exe  (2cf5d5bd7a849c001caf09263cb6bd52)

1 / 68      (Adware)
http://d.unfriendtool.com/UnfriendTool/461/.../Setup.exe  (5c9dc830d4f4ab72ffc3d0c6f8d199bf)

The following 2 files have been seen to comunicate with d.unfriendtool.com in live environments.

URL:
http://d.unfriendtool.com/

Web server:
Apache