file9space.com
Corp New Ventures Services
Domain Information
The domain file9space.com registered by Corp New Ventures Services was initially registered in January of 2016 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in West Chester, Ohio within the United States which resides on the Level 3 Communications, Inc. network.
Registrant:
Corp New Ventures Services
Registrar:
NAME FIND SOURCE LLC
Server location:
Ohio, United States (US)
Create date:
Sunday, January 17, 2016
Expires date:
Tuesday, January 17, 2017
Updated date:
Sunday, January 24, 2016
ASN:
AS30152 BEYOND-HOSTING - Beyond Hosting, LLC,US
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.InstallMetrix.FileVerified (M), PUP.InstallMetrix.FileVeri (M), PUP.InstallMetrix (M)
100.00%
avast!
Win32:Rootkit-gen [Rtk], Win32:Malware-gen, Win32:Adware-gen [Adw]
56.00%
AVG
Adware Generic5.CHSX.dropper, Adware Generic6
56.00%
VIPRE Antivirus
Threat.4150696, Threat.5063683
56.00%
Dr.Web
Trojan.Domaiq.16, Trojan.Domaiq.110, Trojan.Domaiq.7, Trojan.Amonetize.7
56.00%
Zillya! Antivirus
Adware.InstallMonster.Win32.42
56.00%
K7 AntiVirus
Adware
56.00%
NANO AntiVirus
Riskware.Win32.InstallMonster.dhazif
56.00%
F-Prot
W32/A-215008ab
56.00%
Norman
Dropped:Application.Generic.936355, InstallMetrix.E
56.00%
Clam AntiVirus
Win.Adware.Installmetrix-4, Win.Adware.Installmonster-15, Win.Adware.Installmonster-9
56.00%
Kaspersky
not-a-virus:AdWare.Win32.InstallMetrix, not-a-virus:AdWare.Win32.InstallMonster
56.00%
Agnitum Outpost
PUA.InstallMetrix
56.00%
Avira AntiVirus
Adware/InstallMonster.deih.13, Adware/InstallMet.hc, Adware/InstallMonster.deih.49, Adware/InstallMonster.deih.27
56.00%
Vba32 AntiVirus
AdWare.InstallMonster
56.00%
The domain file9space.com has been seen to resolve to the following 3 IP addresses.
8-36-41-57.bhsrv.net
November 17, 2014
File downloads found at URLs served by file9space.com.
Latest 30 of 62 download URLs
The following 2 files have been seen to comunicate with file9space.com in live environments.
URL:
http://file9space.com/