d5.mp3rocket.me

Paschal Rousseau

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the iWeb Technologies Inc. network.
Registrar:
Key-Systems GmbH

Server location:
Quebec, Canada (CA)

ASN:
AS32613 IWEB-AS - iWeb Technologies Inc.,CA

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MP3Support.N, Win32.Generic.Installer.SCCE.Meta, Win32.Generic.SCCE.Installer.Meta, PUP.installCore.MP3TechSupport.Installer (M), PUP.installCore.MP3TechS.Installer (M), PUP.OpenCandy.SCCE.Installer.Meta (M)
100.00%

ESET NOD32
Win32/OpenCandy.A potentially unsafe (variant), Win32/OpenCandy.E potentially unsafe (variant)
50.00%

Dr.Web
Adware.OpenCandy.144, Adware.OpenCandy.171
50.00%

Baidu Antivirus
Adware.Win32.OpenCandy
50.00%

VIPRE Antivirus
Trojan.Win32.Generic, Opencandy
50.00%

Kaspersky
not-a-virus:Downloader.Win32.Agent
50.00%

Sophos
Generic PUA JB
50.00%

avast!
Win32:Malware-gen
50.00%

Bkav FE
W32.HfsAdware
41.67%

McAfee
Artemis!3EB929CA0A36, Artemis!09672008FF00, Artemis!03401FFC6A8D
41.67%

Trend Micro House Call
Suspicious_GEN.F47V0531, Suspicious_GEN.F47V0413, Suspicious_GEN.F47V0418
41.67%

Fortinet FortiGate
Riskware/OpenCandy
41.67%

Zillya! Antivirus
Downloader.Agent.Win32.248040, Downloader.Agent.Win32.260269
41.67%

Agnitum Outpost
Riskware.Agent
41.67%

K7 AntiVirus
Unwanted-Program
41.67%

The domain d5.mp3rocket.me has been seen to resolve to the following 2 IP addresses.

November 7, 2015

April 16, 2014

File downloads found at URLs served by d5.mp3rocket.me.

1 / 68      (PUP)
http://d5.mp3rocket.me/downloads/.../mp3rocket-pro.exe  (819ae919289b4cefc75d467cd21300da)

1 / 68      (Adware)
http://d5.mp3rocket.me/.../mp3rocket.exe  (8d3c3b31dad0275328bd656871d333a6)

1 / 68      (PUP)
http://d5.mp3rocket.me/.../mp3rocket.exe  (b5342f5c74b9ccbc2d69e3bebc940f59)

1 / 68      (Adware)
http://d5.mp3rocket.me/.../mp3rocket.exe  (a05020291cee4ac6b866b23b27c71bea)

21 / 68    (Adware)
http://d5.mp3rocket.me/.../mp3rocket.exe  (e499f4b4fccc72814737d9ac90d5431d)

21 / 68    (Adware)
http://d5.mp3rocket.me/.../mp3rocket.exe  (3737f22c9226b6d48a60faf6b94af61e)

20 / 68    (PUP)
http://d5.mp3rocket.me/.../mp3rocket.exe  (a79ce5f53be8ac6859afb6ad1982cdd4)

8 / 68      (PUP)

1 / 68      (Adware)
http://d5.mp3rocket.me/.../mp3rocket.exe  (c6d97d3397c35d2c244dda3f2c8305eb)

21 / 68    (Adware)
http://d5.mp3rocket.me/.../mp3rocket.exe  (f5fe82201a3225f61be8bb5fc0c7b9ad)

19 / 68    (PUP)
http://d5.mp3rocket.me/.../mp3rocket.exe  (3eb929ca0a36d562ba9f6ef16b38512c)

1 / 68      (PUP)
http://d5.mp3rocket.me/downloads/.../mp3rocket-pro.exe  (beb269e7e56c780484c7859cb6492f17)

URL:
http://d5.mp3rocket.me/

Web server:
Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4