dc172.gulfup.com

FR Group

Domain Information

The domain dc172.gulfup.com registered by FR Group was initially registered in April of 2006 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dronten, Flevoland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Flevoland, Netherlands (NL)

Create date:
Thursday, April 6, 2006

Expires date:
Monday, April 3, 2023

Updated date:
Wednesday, February 25, 2015

ASN:
AS50673 SERVERIUS-AS Serverius Holding B.V.,NL

Root domain:

Scanner detections:
Detections  (75% detected)

Scan engine
Details
Detections

Trend Micro House Call
TROJ_GEN.F47V0809, TROJ_GEN.F47V0831
50.00%

Reason Heuristics
PUP.FreeGamePick, PUP.MyPlayCity.Installer.Meta (L)
50.00%

K7 AntiVirus
Unwanted-Program
25.00%

Sophos
Open Install
25.00%

Dr.Web
Adware.Downware.1348
25.00%

ESET NOD32
Win32/OpenInstall (variant)
25.00%

McAfee
Artemis!3719C6E783EF
25.00%

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
25.00%

ESET NOD32
Detection.Undefined
25.00%

The domain dc172.gulfup.com has been seen to resolve to the following 2 IP addresses.

June 19, 2015

May 30, 2014

File downloads found at URLs served by dc172.gulfup.com.

1 / 68      (inconclusive)

7 / 68      (PUP)

1 / 68      (PUP)
http://dc172.gulfup.com/gg0c3.exe  (atlantis_setup.exe)

2 / 68      (PUP)
http://dc172.gulfup.com/R4OO1.exe  (8-ball-frenzy.exe)

URL:
http://dc172.gulfup.com/

Web server:
gulfup.com