Domains By Proxy, LLC (Proxy Registrant)
The domain data.phpnuke.org is registered by proxy through GoDaddy.com, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Quebec, Canada (CA)
Detections (100% detected)
PUP.Installer.BREEINTERNET, PUP.InffinityInternetSL.N, PUP.SILICOMINTERNETSL.M, Threat.Installer.InffinityInternet, PUP.BREEINTERNET.Installer (M), PUP.MAFERINTERNET.Installer (M), PUP.Inffinity.InffinityInternet.Installer (M), PUP.Inffinity.Installer (M), PUP.InstallCore.Installer.Meta (M), PUP.MAFERINT.Installer (M), PUP.BREEINTE.Installer (M), PUP (M)
Trend Micro House Call
a variant of 2d02221c89951f4f758bec67ac442cde9bf3929a
The domain data.phpnuke.org has been seen to resolve to the following IP address.
May 1, 2014
File downloads found at URLs served by data.phpnuke.org.
The following 2 files have been seen to comunicate with data.phpnuke.org in live environments.
“Phpnuke Programs - (Free) download library”
SSL certificate subject:
CN=*.phpnuke.org, OU=Domain Control Validated
SSL certificate issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc."