d.webshieldonline.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain d.webshieldonline.com is registered by proxy through GODADDY.COM, LLC and was originally registered in September of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Remove Malware from d.webshieldonline.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Tuesday, September 10, 2013

Expires date:
Saturday, September 10, 2016

Updated date:
Thursday, September 10, 2015

Scanner detections:
Detections  (85% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ParallelLinesDevelopment.F, PUP.Installer.ParallelLinesDevelopment.CC, PUP.Installer.Outbrowse, PUP.Injekt.ParallelLinesDevelopment.Installer (M)
91.67%

Dr.Web
Adware.Plugin.128, Adware.Downware.2081
75.00%

Malwarebytes
PUP.Optional.InternetUpdater.A, PUP.Optional.WebShield, PUP.Optional.OutBrowse
75.00%

Agnitum Outpost
PUA.PullUpdate, PUA.OutBrowse
58.33%

VIPRE Antivirus
Adware.Win32.SaMon, Threat.4784459
50.00%

Antiy Labs AVL
Trojan/Win32.SGeneric, Riskware[:not-a-virus]/Win32.OutBrowse.g
50.00%

Kingsoft AntiVirus
VIRUS_UNKNOWN
50.00%

Vba32 AntiVirus
TScope.Trojan.MSIL
50.00%

ESET NOD32
MSIL/Adware.PullUpdate
50.00%

Kaspersky
not-a-virus:AdWare.Win32.SaMon, not-a-virus:AdWare.Win32.OutBrowse
50.00%

Trend Micro House Call
TROJ_GEN.F47V1225, TROJ_GE.0C72B010, TROJ_GEN.F47V0325, TROJ_GE.05C4FC3B
41.67%

McAfee
Artemis!E788D6465D51, Artemis!20CA9FC162BC, Artemis!ECA82EE1E581, Artemis!5390E987C579, Program.Adware-OutBrowse.a
41.67%

K7 Gateway Antivirus
Unwanted-Program
33.33%

K7 AntiVirus
Unwanted-Program
33.33%

Sophos
Generic PUA JF, PUA 'OutBrowse Revenyou'
33.33%

The domain d.webshieldonline.com has been seen to resolve to the following 60 IP addresses.

server-54-192-195-144.iad53.r.cloudfront.net
February 11, 2016

server-54-192-195-78.iad53.r.cloudfront.net
February 11, 2016

server-54-192-195-9.iad53.r.cloudfront.net
February 11, 2016

server-54-192-195-206.iad53.r.cloudfront.net
February 11, 2016

server-54-192-195-203.iad53.r.cloudfront.net
February 11, 2016

server-54-192-195-133.iad53.r.cloudfront.net
February 6, 2016

server-54-192-195-123.iad53.r.cloudfront.net
February 6, 2016

server-54-192-195-97.iad53.r.cloudfront.net
February 6, 2016

server-54-192-195-74.iad53.r.cloudfront.net
February 6, 2016

server-54-192-195-210.iad53.r.cloudfront.net
February 6, 2016

server-54-192-195-199.iad53.r.cloudfront.net
February 6, 2016

server-54-192-195-198.iad53.r.cloudfront.net
February 6, 2016

server-54-192-195-161.iad53.r.cloudfront.net
February 6, 2016

server-54-192-101-102.iad2.r.cloudfront.net
February 12, 2015

server-54-192-101-99.iad2.r.cloudfront.net
February 12, 2015

server-54-192-101-98.iad2.r.cloudfront.net
February 12, 2015

server-54-192-101-86.iad2.r.cloudfront.net
February 12, 2015

server-54-230-102-160.iad2.r.cloudfront.net
February 12, 2015

server-54-230-102-145.iad2.r.cloudfront.net
February 12, 2015

server-54-230-100-125.iad2.r.cloudfront.net
February 12, 2015

server-54-230-100-36.iad2.r.cloudfront.net
February 12, 2015

server-54-230-102-131.iad2.r.cloudfront.net
September 4, 2014

server-54-230-101-139.iad2.r.cloudfront.net
September 4, 2014

server-216-137-33-120.iad2.r.cloudfront.net
September 4, 2014

server-54-230-103-167.iad2.r.cloudfront.net
September 4, 2014

server-54-230-103-112.iad2.r.cloudfront.net
September 4, 2014

server-54-230-103-97.iad2.r.cloudfront.net
September 4, 2014

server-54-230-103-44.iad2.r.cloudfront.net
September 4, 2014

server-54-230-102-254.iad2.r.cloudfront.net
September 4, 2014

server-204-246-169-233.jfk1.r.cloudfront.net
May 1, 2014

 
Showing 30 of 60 IP Addresses

File downloads found at URLs served by d.webshieldonline.com.

1 / 68      (Adware)

0 / 68

21 / 68    (Adware)

1 / 68

3 / 68      (Adware)

19 / 68    (Adware)

19 / 68    (Adware)

13 / 68    (Adware)

9 / 68      (Adware)

12 / 68    (Adware)

16 / 68    (Adware)
http://d.webshieldonline.com/WebShield/4343/.../Setup.exe  (03096bc29c1d47e0ea76a885efd12745)

3 / 68      (Adware)

2 / 68      (Adware)

The following 12 files have been seen to comunicate with d.webshieldonline.com in live environments.

URL:
http://d.webshieldonline.com/

Network:
Amazon Cloudfront

Web server:
AmazonS3

Remove Malware from d.webshieldonline.com - Powered by Reason Core Security