download.phpnuke.org

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download.phpnuke.org is registered by proxy through GoDaddy.com, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Beauharnois, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Registrar:
GoDaddy.com, LLC

Server location:
Quebec, Canada (CA)

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MAFERINT.Installer (M), PUP.Inffinity.Installer (M), PUP.Inffinity (M), PUP (M), PUP.Bibado (M), Adware.Bundler (M)
100.00%

The domain download.phpnuke.org has been seen to resolve to the following 4 IP addresses.

phpnuke.org
July 14, 2016

www.phpnuke.org
July 19, 2015

downloads.phpnuke.org
July 19, 2015

downloads.phpnuke.org
February 1, 2014

File downloads found at URLs served by download.phpnuke.org.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://download.phpnuke.org/o/en/.../installer_acdsee.exe  (2b9edbd264546ec5a3123ab017c5d5bd)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://download.phpnuke.org/o2/da/da28e/.../play89.exe  (ff000316f99e9f44b6fef9a56a473aa6)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://download.phpnuke.org/o2/31/31c52/.../skype.exe  (a33a2859745d7667596ec316a038eba0)

1 / 68      (Adware)

1 / 68      (Adware)

 
Latest 30 of 235 download URLs

The following 9 files have been seen to comunicate with download.phpnuke.org in live environments.

URL:
http://download.phpnuke.org/

SSL certificate subject:
CN=*.phpnuke.org, OU=Domain Control Validated

SSL certificate issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc."

Web server:
nginx