screen317.spywareinfoforum.org

Colston Moore

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Atlanta, Georgia within the United States which resides on the Global Net Access, LLC network.
Registrar:
GoDaddy.com, LLC (R91-LROR)

Server location:
Georgia, United States (US)

ASN:
AS16626 GNAXNET-AS - Global Net Access, LLC,US

Scanner detections:
Detections  (65% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SecurityCheck.Installer.Meta, PUP.SecurityCheck.Meta, PUP.SecurityCheck (L), PUP.SecurityCheck.Meta (L), PUP.SecurityCheck.Installer.Meta (L)
70.00%

Trend Micro House Call
TROJ_GEN.R0C1H01GN13, TROJ_GEN.R0CBH0AL813, TROJ_GEN.R0CBH0AJD13, TROJ_GEN.F47V1125, TROJ_GEN.R0CBH0AKO13, TROJ_GEN.R047H0AAF14, TROJ_GEN.F47V0320, TROJ_GEN.F47V0921, TROJ_GEN.F47V0418, TROJ_GEN.F47V0511, Suspicious_GEN.F47V1117, Suspicious_GEN.F47V1128, Suspicious_GEN.F47V1212, Suspicious_GEN.F47V0612
60.00%

Sophos
NirCmd, PUA 'NirCmd'
15.00%

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
15.00%

Qihoo 360 Security
Malware.QVM06.Gen, HEUR/Malware.QVM06.Gen, virus.bat.startmuch.a
15.00%

Panda Antivirus
Trj/Genetic.gen
10.00%

McAfee
Artemis!1482C4A24227, Artemis!76C4D0DBFBB8, Artemis!1A0DCB7C514C
7.50%

SUPERAntiSpyware
Trojan.Agent/Gen-Banker, Trojan.Agent/Gen-Chifrax
5.00%

Norman
Suspicious_Gen4.EGRSE, Suspicious_Gen4.ECCFC
5.00%

Clam AntiVirus
Win.Trojan.Autoit-1369
2.50%

AegisLab AV Signature
Troj.W32.Gen
2.50%

VIPRE Antivirus
Trojan.Win32.Generic
2.50%

The domain screen317.spywareinfoforum.org has been seen to resolve to the following 2 IP addresses.

host-52-116.177.198.simplehelix.com
April 23, 2014

www.spywareinfoforum.com
August 4, 2013

File downloads found at URLs served by screen317.spywareinfoforum.org.

1 / 68      (PUP)
http://screen317.spywareinfoforum.org/SecurityCheck.exe  (532b39bf3f75005ea5fa947a6c1d2389)

URL:
http://screen317.spywareinfoforum.org/

Google Analytics:
UA-12624038

Title:
“http://screen317.spywareinfoforum.org/”

Web server:
Apache

Facebook:
Shares:  1

Statistics are for the previous month.