pchealthboost.com

Boost Software, Inc

Domain Information

The domain pchealthboost.com registered by Boost Software, Inc was initially registered in June of 2010 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Chicago, Illinois within the United States which resides on the Incapsula Inc network.
Registrar:
GODADDY.COM, LLC

Server location:
Illinois, United States (US)

Create date:
Wednesday, June 09, 2010

Expires date:
Tuesday, June 09, 2020

Updated date:
Tuesday, June 09, 2015

ASN:
AS19551 INCAPSULA Incapsula.com

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.U, PUP.Optional.Installer.T, PUP.Optional.BoostSoftware.a, Threat.Installer.BoostSoftware, Win32.Generic.BoostSoftware.Installer.Meta, PUP.PCHealthBoost, PUP.InstallCore.RE.Installer (M)
100.00%

Rising Antivirus
PE:Trojan.Agent!6.250, PE:Malware.XPACK-LNR/Heur!1.5594, PE:AdWare.Win32.Eorezo.a!1075356178
38.89%

Dr.Web
infected with BackDoor.Infector.133, riskware program Program.Unwanted.123, Trojan.Packed.28474, Adware.Downware.8416, riskware program Program.Unwanted.120
36.11%

Vba32 AntiVirus
Signed-Riskware.PCHealthBoost, Downware.InstallCore
33.33%

AVG
Boostsoft, PCSB
30.56%

Sophos
Install Core Click run software, PUA 'Install Core Click run software'
30.56%

G Data
Win32.Application.PCHealthBoost
30.56%

ESET NOD32
Win32/Distromatic.C potentially unwanted application, Win32/InstallCore.FF potentially unwanted application, Detection.Undefined
22.22%

IKARUS anti.virus
PUA.PCSpeedBoost, PUA.Distromatic
22.22%

Jiangmin
Backdoor/RBot.abfr
16.67%

Qihoo 360 Security
Malware.QVM05.Gen
16.67%

K7 Gateway Antivirus
Unwanted-Program , Dialer , Riskware
16.67%

K7 AntiVirus
Unwanted-Program , Riskware
13.89%

Trend Micro House Call
TROJ_GEN.F47V1206, Suspicious_GEN.F47V0909
8.33%

Avira AntiVirus
ADWARE/InstallCore.Gen9
8.33%

The domain pchealthboost.com has been seen to resolve to the following 10 IP addresses.

June 18, 2015

June 18, 2015

May 2, 2015

May 2, 2015

May 2, 2015

May 2, 2015

May 2, 2015

199.83.134.104.ip.incapdns.net
January 14, 2014

199.83.132.104.ip.incapdns.net
January 14, 2014

August 5, 2013

File downloads found at URLs served by pchealthboost.com.

4 / 68      (PUP)

2 / 68      (PUP)
http://pchealthboost.com/lp/.../download-now.php  (9d30614800cd6e0af66350b08bd16e0b.exe)

1 / 68      (Adware)

3 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

3 / 68      (PUP)

1 / 68      (PUP)

4 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (PUP)

1 / 68      (PUP)

4 / 68      (PUP)

3 / 68      (PUP)

4 / 68      (PUP)

3 / 68      (PUP)

 
Latest 30 of 91 download URLs

August 5, 2013

February 6, 2014

January 14, 2014

URL:
http://pchealthboost.com/

Title:
“PC HealthBoost® — Clean Up Your PC”

SSL certificate subject:
CN=sni104473.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx (PHP/5.5.33)

Facebook:
Likes:  41
Shares:  53
Comments:  10

Statistics above are for the previous month of August 2017.