installers.phpnuke.org

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain installers.phpnuke.org is registered by proxy through GoDaddy.com, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Beauharnois, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Remove Malware from installers.phpnuke.org - Powered by Reason Core Security
Registrar:
GoDaddy.com, LLC

Server location:
Quebec, Canada (CA)

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.QUALITYSCORESL.M, PUP.installCore.DestinyDreamSA.Installer (M), PUP.installCore.DestinyDreamSA (M), PUP.installCore.SoftInstall.Installer (M), PUP.Bibado.BibadoInvestments.Bundler (M), PUP.installCore.SILICOMINTERNET (M)
100.00%

K7 AntiVirus
Unwanted-Program , Trojan
14.58%

Dr.Web
Trojan.InstallCore.41, Trojan.Packed.28498, Trojan.InstallCore.15
14.58%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696
14.58%

Avira AntiVirus
Adware/InstallCore.772256, ADWARE/InstallCore.Gen9, Adware/InstallCore.771128, ADWARE/InstallCore.Gen7, ADWARE/InstallCo.RY
14.58%

AVG
Generic
14.58%

Comodo Security
Application.Win32.InstallCore.DZ, Application.Win32.InstallCore.DRZ, Application.Win32.InstallCore.DSQ
12.50%

ESET NOD32
Win32/InstallCore.PK potentially unwanted application, Win32/InstallCore.UQ potentially unwanted application, Win32/InstallCore.UE potentially unwanted application
12.50%

K7 Gateway Antivirus
Unwanted-Program , Trojan
12.50%

McAfee Web Gateway
Artemis, BehavesLike.Win32.CryptInno.bc
10.42%

NANO AntiVirus
Riskware.Win32.InstallCore.dmfogu, Riskware.Win32.InstallCore.dmfoic, Riskware.Win32.InstallCore.dmkfla
8.33%

Sophos
Install Core Click run software, PUA 'Install Core Click run software'
8.33%

McAfee
Artemis!2F7A90BC610C, Artemis!C0A9F938D88C, Artemis!92DD3E43969A
8.33%

avast!
Win32:Malware-gen, PUP-gen [PUP], Oncer
8.33%

Baidu Antivirus
Adware.Win32.InstallCore
6.25%

The domain installers.phpnuke.org has been seen to resolve to the following 2 IP addresses.

www.phpnuke.org
May 28, 2015

downloads.phpnuke.org
June 9, 2014

File downloads found at URLs served by installers.phpnuke.org.

1 / 68      (Adware)
https://installers.phpnuke.org/?ic_user_id=432  (adobe-photoshop-cs5-12.0.3.exe)

1 / 68      (Adware)
https://installers.phpnuke.org/?ic_user_id=327  (lan-desktop-spy-monitor-4.1.exe)

1 / 68      (Adware)

URL:
http://installers.phpnuke.org/

Google Analytics:
UA-15728026

Title:
“Phpnuke Programs - (Free) download library”

SSL certificate subject:
CN=*.phpnuke.org, OU=Domain Control Validated

SSL certificate issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc."

Web server:
nginx

Remove Malware from installers.phpnuke.org - Powered by Reason Core Security