d9.mp3rocket.me

Paschal Rousseau

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the iWeb Technologies Inc. network.
Registrar:
Key-Systems GmbH

Server location:
Quebec, Canada (CA)

ASN:
AS32613 IWEB-AS - iWeb Technologies Inc.,CA

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MP3Support.L, PUP.MP3Support.O, PUP.MP3Support.J, PUP.Installer.MP3Support, PUP.installCore.MP3TechSupport.Installer (M), Win32.Generic.SCCE.Installer.Meta, PUP.OpenCandy.SCCE.Installer.Meta (M), PUP.installCore.MP3TechS.Installer (M)
100.00%

ESET NOD32
Win32/OpenCandy, Win32/Bundled.Toolbar.Ask (variant), Win32/InstallCore.PL (variant), Win32/OpenCandy.A potentially unsafe (variant), Win32/OpenCandy.E potentially unsafe (variant)
60.00%

Fortinet FortiGate
Riskware/OpenCandy
53.33%

Dr.Web
Program.Unwanted.62, Adware.OpenCandy.163, Adware.OpenCandy.171
53.33%

K7 AntiVirus
Unwanted-Program
53.33%

Bkav FE
W32.Clod284.Trojan, W32.HfsAdware
46.67%

Trend Micro House Call
TROJ_GEN.F47V0828, Suspicious_GEN.F47V0418, Suspicious_GEN.F47V0413
46.67%

Zillya! Antivirus
Downloader.Agent.Win32.260269, Trojan.Kryptik.Win32.805012
46.67%

VIPRE Antivirus
Trojan.Win32.Generic, Opencandy
46.67%

Baidu Antivirus
Adware.Win32.OpenCandy
46.67%

McAfee
Artemis!9834C63403AD, Artemis!09672008FF00, Artemis!997BFFD78835, Artemis!03401FFC6A8D
40.00%

Agnitum Outpost
Riskware.Agent
40.00%

Kaspersky
not-a-virus:Downloader.Win32.Agent
40.00%

Sophos
Generic PUA JB
40.00%

G Data
Win32.Trojan.Agent.95WKEY
40.00%

The domain d9.mp3rocket.me has been seen to resolve to the following 3 IP addresses.

June 28, 2016

May 4, 2015

September 5, 2014

File downloads found at URLs served by d9.mp3rocket.me.

1 / 68      (Adware)
http://d9.mp3rocket.me/.../mp3rocket.exe  (8d3c3b31dad0275328bd656871d333a6)

11 / 68    (PUP)
http://d9.mp3rocket.me/.../mp3rocket.exe  (00ba345387c68fcea2189ff3cd19296a)

1 / 68      (PUP)
http://d9.mp3rocket.me/.../mp3rocket.exe  (b5342f5c74b9ccbc2d69e3bebc940f59)

21 / 68    (Adware)
http://d9.mp3rocket.me/.../mp3rocket.exe  (df3509664eaa1528472b3aafda42b1d5)

1 / 68      (Adware)
http://d9.mp3rocket.me/.../mp3rocket.exe  (c6d97d3397c35d2c244dda3f2c8305eb)

19 / 68    (Adware)
http://d9.mp3rocket.me/.../mp3rocket.exe  (9834c63403ad5601532a128219c3e684)

2 / 68      (PUP)
http://d9.mp3rocket.me/.../mp3rocket.exe  (9c3c551035f02c398db72a9ef918ce3b)

1 / 68      (PUP)
http://d9.mp3rocket.me/.../mp3rocket.exe  (96ec3dfd209ec7dd9e6feea46b96ccd1)

20 / 68    (PUP)
http://d9.mp3rocket.me/.../mp3rocket.exe  (997bffd788356ff34331cf5114467c69)

21 / 68    (Adware)
http://d9.mp3rocket.me/.../mp3rocket.exe  (78f3126e103daa6563f3bc4339e98887)

18 / 68    (Adware)
http://d9.mp3rocket.me/.../mp3rocket.exe  (99dc353239c0324f5d3b1d3318cf2cbf)

2 / 68      (PUP)
http://d9.mp3rocket.me/.../mp3rocket.exe  (369d6b8650beb97d69d839bd941bc2c2)

20 / 68    (PUP)
http://d9.mp3rocket.me/.../mp3rocket.exe  (a79ce5f53be8ac6859afb6ad1982cdd4)

5 / 68      (PUP)
http://d9.mp3rocket.me/.../mp3rocket.exe  (7f7dd60ab8a2108c88ad15ab787eaf0c)

7 / 68      (PUP)

URL:
http://d9.mp3rocket.me/

Web server:
Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 PHP/5.4.22