mp3wm.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain mp3wm.com is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2009. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Saturday, October 17, 2009

Expires date:
Monday, October 17, 2016

Updated date:
Tuesday, August 25, 2015

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SITEONSPOT.EE, PUP.Somoto.g, PUP.Somoto.CC, PUP.Somoto.DD, PUP.Somoto.Bundler (M)
100.00%

SUPERAntiSpyware
PUP.Somoto/Variant
50.00%

Clam AntiVirus
Win.Adware.Somoto
50.00%

NANO AntiVirus
Riskware.Nsis.Adware.dbnhrj
50.00%

Sophos
Somoto BetterInstaller
50.00%

Avira AntiVirus
APPL/Somoto.hzis, APPL/Somoto.Gen2
50.00%

AVG
Generic
50.00%

VIPRE Antivirus
Threat.4783461, Trojan.Win32.Generic
37.50%

Dr.Web
Trojan.Packed.26824, Trojan.Packed.28357
37.50%

avast!
Somoto-P [PUP], Win32:Somoto-R [PUP]
37.50%

Baidu Antivirus
Adware.Win32.Agent, Adware.Win32.Somoto
37.50%

K7 AntiVirus
Unwanted-Program
37.50%

Comodo Security
Application.Win32.Somoto.CK
37.50%

AhnLab V3 Security
Win-PUP/Somoto
37.50%

Qihoo 360 Security
Win32/Application.6bb, HEUR/QVM42.0.Malware.Gen
37.50%

The domain mp3wm.com has been seen to resolve to the following 2 IP addresses.

February 24, 2016

February 24, 2016

File downloads found at URLs served by mp3wm.com.

21 / 68    (Adware)

16 / 68    (Adware)

13 / 68    (Adware)

1 / 68      (Adware)

26 / 68    (Adware)
http://mp3wm.com/.../Hot_Water_Music_Drag_My_BodySetup-IdCoADLlx.exe  (windows_loader_v2_downloader-ifesai5lt.exe)

1 / 68      (Adware)

1 / 68      (Adware)

URL:
http://mp3wm.com/

Google Analytics:
UA-10142259

Title:
“Pesquisa e download de Músicas para Baixar”

Description:
“Baixe Músicas MP3, Totalmente Grátis para Download.”

SSL certificate subject:
CN=sni11505.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx (PHP/5.3.28)