s1.vipboxsportsapp.com

WHOIS PRIVACY PROTECTION SERVICE, INC.  (Proxy Registrant)

Domain Information

The domain s1.vipboxsportsapp.com is registered by proxy through ENOM, INC. and was originally registered in September of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in London, England within United Kingdom which resides on the RIPE Network Coordination Centre network.
Remove Malware from s1.vipboxsportsapp.com - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
England, United Kingdom (GB)

Create date:
Thursday, September 13, 2012

Expires date:
Tuesday, September 13, 2016

Updated date:
Tuesday, January 12, 2016

ASN:
AS17025 ABOVENET-CUSTOMER - Abovenet Communications, Inc,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.TerraFirmaInternetConsulting.Z, PUP.Installer.CoolMirageltd.Z, PUP.TerraFirmaInternetConsulting.Installer (M), PUP.CoolMirage.Installer (M)
100.00%

Dr.Web
Adware.Downware.902, Adware.Downware.861, Adware.Downware.573, Adware.Downware.487
60.00%

avast!
Win32:Downloader-TPG [PUP], NSIS:Oneclick-Z [PUP]
50.00%

SUPERAntiSpyware
Adware.Downware, PUP.BundleInstaller
50.00%

Comodo Security
Application.Win32.MCool.A, Application.Win32.Agent.Y, Application.Win32.Downware.G
50.00%

VIPRE Antivirus
Iminent
50.00%

Avira AntiVirus
APPL/CoolMirage.Gen6, ADWARE/Adware.Gen6
50.00%

ESET NOD32
Win32/Adware.1ClickDownload, Win32/Adware.1ClickDownload.AM
40.00%

Sophos
FT Downloader, 1 Click Downloader, 1 Click Downloader (PUA)
40.00%

NANO AntiVirus
Riskware.Nsis.Downware.yrefc, Trojan.Script.Downware.cujzax, Riskware.Nsis.Downware.czyjkl
40.00%

McAfee
Artemis!710BFCC07BFC, Artemis!78BE91942ABC, Adware-SweetIM
30.00%

McAfee Web Gateway
Artemis!710BFCC07BFC, Artemis!78BE91942ABC, BehavesLike.Win32.Suspicious.dc
30.00%

Fortinet FortiGate
Riskware/1ClickDownload
20.00%

Trend Micro House Call
TROJ_GEN.F47V1115, TROJ_GEN.F47V0424
20.00%

Malwarebytes
PUP.BundleInstaller.DW
10.00%

The domain s1.vipboxsportsapp.com has been seen to resolve to the following 3 IP addresses.

February 13, 2016

94.31.29.96.IPYX-077437-ZYO.above.net
September 1, 2015

December 18, 2013

File downloads found at URLs served by s1.vipboxsportsapp.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

15 / 68    (Adware)

9 / 68      (Adware)

13 / 68    (Adware)

6 / 68      (Adware)

8 / 68      (Adware)

12 / 68    (Adware)

3 / 68      (Adware)

The following 7 files have been seen to comunicate with s1.vipboxsportsapp.com in live environments.

URL:
http://s1.vipboxsportsapp.com/

Google Analytics:
UA-2249740

Title:
“Vipboxsportsapp.com”

Description:
“Find Cash Advance, Debt Consolidation and more at Vipboxsportsapp.com. Get the best of Insurance or Free Credit Report, browse our section on Cell Phones or learn about Life Insurance. Vipboxsportsapp.com is the site for Cash Advance.”

Web server:
Microsoft-IIS/8.5 (ASP.NET) (Version: 4.0.30319)

Facebook:
Shares:  2
Comments:  2

Statistics are for the previous month.

30 of 298 related domains

Remove Malware from s1.vipboxsportsapp.com - Powered by Reason Core Security