liversia.net

Ben Dal

Domain Information

The domain liversia.net registered by Ben Dal was initially registered in July of 2014 through DOMAINSITE, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Kirkland, Washington within the United States which resides on the eNom, Incorporated network.
Registrar:
DOMAINSITE, INC.

Server location:
Washington, United States (US)

Create date:
Wednesday, July 30, 2014

Expires date:
Saturday, July 30, 2016

Updated date:
Tuesday, September 16, 2014

ASN:
AS21740 ENOMAS1 - eNom, Incorporated,US

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

avast!
Win32:Agent-AYLT [PUP], Win32:MultiPlug-JU [PUP], Win32:FakeDownload-G [PUP]
56.25%

ESET NOD32
Win32/Adware.MultiPlug.DR application, Win32/Adware.MultiPlug.DZ application, Win32/AdWare.MultiPlug.CT application, Win32/Adware.MultiPlug.JX application, Win32/Adware.MultiPlug.DM application, Win32/Adware.MultiPlug.DP application
52.08%

Norman
Gen:Variant.Adware.Mplug.21, Gen:Variant.Downloader.188, Gen:Variant.Adware.MPlug.16, Gen:Variant.Adware.MultiPlug.4, Gen:Variant.Adware.Kazy.511922
50.00%

Dr.Web
Trojan.Crossrider.36840, Trojan.WebPick.3154, Trojan.Crossrider.37471, Trojan.WebPick.3172
45.83%

Reason Heuristics
PUP.OlehAlek (M), Threat.Win.Reputation.IMP, Adware.Generic.AT (M), PUP (M), PUP.Bundler (M)
45.83%

AVG
Adware Generic_r.WW, Adware Generic_r.XD, Adware Generic_r.VD, Adware Generic_r.UH, Adware Generic5.CKOK, Adware Generic5.CKNS, Adware Generic5.CKOW
43.75%

Emsisoft Anti-Malware
Gen:Variant.Adware.Mplug.21, Gen:Variant.Downloader.188, Gen:Variant.Adware.MPlug.16, Gen:Variant.Adware.MultiPlug, Gen:Variant.Adware.Kazy.511922
41.67%

Microsoft Security Essentials
Threat.Undefined, BrowserModifier:Win32/Diplugem
39.58%

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug, not-a-virus:HEUR:AdWare.Win32.MultiPlug
31.25%

McAfee
Program.MultiPlug-FSZ, Program.MultiPlug-FTA, Program.MultiPlug-FRO, Program.MultiPlug-FRC, Program.MultiPlug-FTG, Program.MultiPlug-FSS
22.92%

F-Secure
Variant.Downloader.188, Variant.Adware.MPlug, Variant.Adware.MultiPlug, Variant.Adware.Kazy, Variant.Razy.5723
16.67%

VIPRE Antivirus
Threat.5180739, Threat.5085665
12.50%

Sophos
PUA 'MultiPlug' (of type Adware)
2.08%

The domain liversia.net has been seen to resolve to the following 11 IP addresses.

rc2.sjl01.dmtracker.com
August 2, 2016

ec2-52-27-166-51.us-west-2.compute.amazonaws.com
July 19, 2015

ec2-52-27-146-26.us-west-2.compute.amazonaws.com
July 19, 2015

ec2-52-26-71-172.us-west-2.compute.amazonaws.com
July 19, 2015

ec2-52-24-161-49.us-west-2.compute.amazonaws.com
June 30, 2015

ec2-54-69-104-255.us-west-2.compute.amazonaws.com
May 3, 2015

ec2-54-68-145-207.us-west-2.compute.amazonaws.com
December 30, 2014

ec2-54-148-67-213.us-west-2.compute.amazonaws.com
November 29, 2014

ec2-54-68-171-13.us-west-2.compute.amazonaws.com
November 29, 2014

ec2-54-68-142-187.us-west-2.compute.amazonaws.com
September 27, 2014

ec2-54-68-85-18.us-west-2.compute.amazonaws.com
September 27, 2014

File downloads found at URLs served by liversia.net.

 
Latest 30 of 122 download URLs

The following 38 files have been seen to comunicate with liversia.net in live environments.

 
Latest 20 of 51 files

URL:
http://liversia.net/

Web server:
ngx_openresty (PHP/5.4.37)