download.phpnuke.org

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download.phpnuke.org is registered by proxy through GoDaddy.com, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Beauharnois, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Remove Malware from download.phpnuke.org - Powered by Reason Core Security
Registrar:
GoDaddy.com, LLC

Server location:
Quebec, Canada (CA)

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.BIBADOINVESTMENTS.V, PUP.InffinityInternet.W, PUP.BIBADOINVESTMENTS.K, PUP.InffinityInternet.Q, PUP.MAFERINTERNETSL.I, PUP.InffinityInternet.T, PUP.MAFERINTERNETSL.G, PUP.InffinityInternetSL.V, PUP.InffinityInternetSL.R, PUP.InffinityInternet.AA, PUP.InffinityInternet.Z, PUP.BIBADOINVESTMENTS.EE, PUP.BIBADOINVESTMENTS.I, PUP.BIBADOINVESTMENTS.P, PUP.InffinityInternet.X, PUP.InffinityInternet.R, PUP.InffinityInternet.b, PUP.Bibado, PUP.Installer.InffinityInternet, PUP.InffinityInternet.Installer (M), PUP.Bibado.BIBADOINVESTMENTS.Bundler (M), PUP.Inffinity.InffinityInternet.Installer (M)
94.44%

Dr.Web
Adware.Downware.23, Adware.Downware.174, Trojan.Damaged.1, Threat.Undefined, Adware.Downware.1036, Adware.Downware.834, infected with Trojan.DownLoader1.46640
44.44%

ESET NOD32
Win32/Toggle potentially unwanted application, Win32/Toggle.D.Gen potentially unwanted application, Win32/Toggle.H potentially unwanted application
44.44%

VIPRE Antivirus
Threat.4150696, Threat.4786062, Conduit
33.33%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, AdWare.Inffinity
33.33%

K7 Gateway Antivirus
Trojan , Unwanted-Program
30.56%

avast!
Toggle-A [PUP], Win32:Toggle-A [PUP], Installer-Z [PUP], Toggle-D [PUP]
27.78%

Avira AntiVirus
ADWARE/Adware.Gen2, TR/Trash.Gen, APPL/Toggle.pika, ADWARE/Adware.Gen4
27.78%

K7 AntiVirus
Unwanted-Program
25.00%

NANO AntiVirus
Riskware.Win32.Downware.dagvri, Riskware.Nsis.Babylon.cwhyhv, Riskware.Nsis.Adware.dcnawc
19.44%

Malwarebytes
PUP.BundleInstaller.PHP, PUP.BundleInstaller.DT, PUP.Adbundler, PUP.SmsPay.PGen, PUP.BundleInstaller.BT
19.44%

Kaspersky
not-a-virus:AdWare.Win32.Inffinity, not-a-virus:HEUR:AdWare.NSIS.Gottle
19.44%

Antiy Labs AVL
Trojan/Win32.SGeneric, GrayWare[AdWare:not-a-virus]/Win32.Inffinity.yas, Spyware[AdWare:not-a-virus]/Win32.Inffinity
16.67%

SUPERAntiSpyware
Trojan.Agent/Gen-Toggle, Trojan.Agent/Gen-Nullo[Short], Adware.Toggle
16.67%

Sophos
Bibado, PUA 'Bibado'
16.67%

The domain download.phpnuke.org has been seen to resolve to the following 3 IP addresses.

www.phpnuke.org
July 19, 2015

downloads.phpnuke.org
July 19, 2015

downloads.phpnuke.org
February 1, 2014

File downloads found at URLs served by download.phpnuke.org.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

8 / 68      (Adware)
http://download.phpnuke.org/o2/f3/f3b85/.../the_sims.exe  (13fc39a9643c626e4bcd05de4cb29643)

1 / 68      (Adware)
http://download.phpnuke.org/o/en/.../installer_skype.exe  (cc45ce1f69fde503fbb94060f85919b6)

10 / 68    (Adware)

9 / 68      (Adware)

9 / 68      (Adware)

9 / 68      (Adware)

17 / 68    (Adware)

17 / 68    (Adware)

7 / 68      (Adware)

1 / 68      (Adware)
http://download.phpnuke.org/o2/66/66a61/.../paintnet.exe  (f709846c6390cdab195b13800cedc3e1)

5 / 68      (Adware)

15 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

 
Latest 30 of 36 download URLs

URL:
http://download.phpnuke.org/

SSL certificate subject:
CN=*.phpnuke.org, OU=Domain Control Validated

SSL certificate issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc."

Web server:
nginx

Remove Malware from download.phpnuke.org - Powered by Reason Core Security