installers.phpnuke.org

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain installers.phpnuke.org is registered by proxy through GoDaddy.com, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Beauharnois, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Registrar:
GoDaddy.com, LLC

Server location:
Quebec, Canada (CA)

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Detections  (58% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.installCore (M)
100.00%

The domain installers.phpnuke.org has been seen to resolve to the following 2 IP addresses.

www.phpnuke.org
May 28, 2015

downloads.phpnuke.org
June 9, 2014

File downloads found at URLs served by installers.phpnuke.org.

1 / 68      (Adware)
https://installers.phpnuke.org/?ic_user_id=9237  (wifi-unlocker-2.0-1.1.2.exe)

1 / 68      (Adware)

1 / 68      (Adware)
https://installers.phpnuke.org/?ic_user_id=432  (microsoft-access-2013-15.0.4420.1017.exe)

The following 2 files have been seen to comunicate with installers.phpnuke.org in live environments.

URL:
http://installers.phpnuke.org/

Google Analytics:
UA-15728026

Title:
“Phpnuke Programs - (Free) download library”

SSL certificate subject:
CN=*.phpnuke.org, OU=Domain Control Validated

SSL certificate issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc."

Web server:
nginx