Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2006. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Salem, Oregon within the United States which resides on the Liquid Web, Inc. network.

Server location:
Oregon, United States (US)

Create date:
Friday, October 06, 2006

Expires date:
Thursday, February 02, 2017

Updated date:
Sunday, November 08, 2015

AS32244 LIQUID-WEB-INC - Liquid Web, Inc.

Scanner detections:
Detections  (73% detected)

Scan engine

Reason Heuristics
PUP.Optional.Installer.ONEUP.X, PUP.Optional.Installer.V, PUP.Optional.Installer.BB, PUP.Optional.Installer.X, Win32.Generic

The domain has been seen to resolve to the following IP address.
February 20, 2014

File downloads found at URLs served by

0 / 68

1 / 68      (Malware)  (28a2a80ec3d31ae1a6431f3e3206d4b5)

0 / 68  (3432d89a038878abfa25c2c03dfa9814)

1 / 68      (PUP)

0 / 68  (b7e9c248bb975791314726e35ae13e12)

1 / 68      (PUP)  (9cc50dedd2f9ec8c11870604c253e0ee)

1 / 68      (Malware)  (0a42af074134430f61a248a4105d2a58)

1 / 68      (PUP)

1 / 68      (PUP)  (076bbf26e999228b69c2410449b925ab)

1 / 68      (PUP)  (fc491a969f8e88bf0f772816479baa7d)

1 / 68      (PUP)  (convertvid_installer v.

1 / 68      (PUP)  (ea20d219c6b08c6e326b163e72e4ae6b)

1 / 68      (PUP)  (8b39991586e763db5c9fcee2ce4ff8c2)

The following 7 files have been seen to comunicate with in live environments.

December 1, 2014


Google Analytics:

“Nuclear Coffee VideoGet. Download YouTube Videos”

“With Nuclear Coffee products you can download videos from video-sharing websites like YouTube, Metacafe, Yahoo Video and many-many more using VideoGet program. Futhermore, VideoGet will automaticaly convert downloaded video for you into desired v...”

SSL certificate subject:, OU=Domain Control Validated

SSL certificate issuer:
CN=Starfield Secure Certificate Authority - G2, OU=, O="Starfield Technologies, Inc."

Web server:
Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 (PHP/5.2.17)

Shares:  1

Statistics above are for the previous month of February 2018.