origin-ics.fivemillionfriends.com

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain origin-ics.fivemillionfriends.com is registered by proxy through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM and was originally registered in January of 2006. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Austin, Texas within the United States which resides on the YHC Corporation network.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Texas, United States (US)

Create date:
Monday, January 23, 2006

Expires date:
Monday, January 23, 2017

Updated date:
Sunday, January 24, 2016

ASN:
AS40034 CONFLUENCE-NETWORK-INC - Confluence Networks Inc,VG

Scanner detections:
Detections  (67% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.BundloreLimited.F, PUP.Installer.appbundler.J, PUP.Pinball.Installer, PUP.Pinball.appbundler.Installer (M)
66.67%

avast!
JS:ScriptIP-inf [Trj], Win32:Zango-AQ [PUP]
50.00%

Avira AntiVirus
W32/Sality.AT, TR/Dropper.Gen, TR/Graftor.1098, ADWARE/Adware.Gen, TR/Spy.Gen4
41.67%

Dr.Web
Win32.Sector.21, Adware.Downware.1598, Adware.Hotbar.700
41.67%

F-Prot
W32/Sality.gen2, W32/HotBar.L.gen, W32/HotBar.O2.gen
33.33%

Microsoft Security Essentials
Threat.Undefined, Adware:Win32/Hotbar
33.33%

IKARUS anti.virus
Trojan-Dropper, not-a-virus:WebToolbar.Win32, Win32.SuspectCrc, not-a-virus:WebToolbar.Win32.Zango
33.33%

ESET NOD32
Win32/Bundlore (variant), Win32/Adware.HotBar (variant)
25.00%

Emsisoft Anti-Malware
Gen:Variant.Adware.Hotbar, Win32.SuspectCrc!IK, Riskware.WebToolbar.Win32.Zango!IK
25.00%

VIPRE Antivirus
Threat.4672643, Pinball Corporation.
25.00%

AVG
Adware Skodna.Generic_r.BM, Zango
25.00%

Kaspersky
not-a-virus:AdWare.Win32.ScreenSaver
25.00%

Quick Heal
Adware.Rugo.A, Adware.Hotbar.AZ4
25.00%

McAfee
Adware-HotBar.d
25.00%

K7 AntiVirus
Adware
25.00%

The domain origin-ics.fivemillionfriends.com has been seen to resolve to the following 4 IP addresses.

209-99-40-223.fwd.datafoundry.com
February 12, 2016

209-99-40-222.fwd.datafoundry.com
January 30, 2016

September 3, 2014

February 6, 2014

File downloads found at URLs served by origin-ics.fivemillionfriends.com.

1 / 68      (Adware)

1 / 68      (Adware)

30 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

29 / 68    (Adware)

42 / 68    (Adware)

1 / 68      (inconclusive)

1 / 68      (inconclusive)

1 / 68      (inconclusive)

The following 3 files have been seen to comunicate with origin-ics.fivemillionfriends.com in live environments.

URL:
http://origin-ics.fivemillionfriends.com/

Web server:
Apache

Facebook:
Shares:  1

Statistics are for the previous month.