d3.blupak.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain d3.blupak.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Zurich, Zurich within Switzerland which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Zurich, Switzerland (CH)

Create date:
Wednesday, March 27, 2013

Expires date:
Sunday, March 27, 2016

Updated date:
Monday, May 11, 2015

ASN:
AS19905 NEUSTAR-AS6 - NeuStar, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.bundlebeez.Installer (M), PUP.bundlebe.Installer (M), PUP.INSTALLI.Installer (M)
100.00%

ESET NOD32
Win32/Adware.TrueDownloader.A application
33.33%

avast!
Win32:Evo-gen [Susp]
33.33%

VIPRE Antivirus
Threat.5065747
33.33%

AVG
Adware Generic6
33.33%

Bkav FE
W32.HfsAdware
33.33%

K7 AntiVirus
Adware
33.33%

Comodo Security
Application.Win32.TrueDown.GIIG
33.33%

Avira AntiVirus
ADWARE/TrueDown.glo
33.33%

IKARUS anti.virus
PUA.TrueDownloader
33.33%

The domain d3.blupak.com has been seen to resolve to the following 2 IP addresses.

June 6, 2016

February 13, 2016

File downloads found at URLs served by d3.blupak.com.

The following 5 files have been seen to comunicate with d3.blupak.com in live environments.

URL:
http://d3.blupak.com/

Title:
“blupak.com”

Web server:
Apache