tools.safezone.cc

Private person  (Proxy Registrant)

Domain Information

The domain tools.safezone.cc is registered by proxy through REGTIME LTD. and was originally registered in January of 2011. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Kiev, Kyyiv within Ukraine which resides on the RIPE Network Coordination Centre network.
Remove Malware from tools.safezone.cc - Powered by Reason Core Security
Registrar:
REGTIME LTD.

Server location:
Kyyiv, Ukraine (UA)

Create date:
Monday, January 31, 2011

Updated date:
Wednesday, October 29, 2014

ASN:
AS42331 FREEHOST PE Freehost,UA

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SafeZone.glax24safezonecc.Meta, PUP.SecurityCheck.glax24safezonecc.Meta, PUP.SafeZone.glax24safezonecc.Meta (M)
100.00%

Vba32 AntiVirus
Trojan-Downloader.Autoit.gen, Trojan.Autoit.F
80.00%

Trend Micro House Call
TROJ_GEN.F47V0322, Suspicious_GEN.F47V1229, Suspicious_GEN.F47V0415
60.00%

Qihoo 360 Security
Malware.QVM10.Gen, HEUR/Malware.QVM11.Gen, HEUR/QVM11.1.Malware.Gen
60.00%

McAfee Web Gateway
BehavesLike.Win32.Dropper.gc
40.00%

Commtouch SDK
W32/GenBl.3A3D4A5E!Olympus
20.00%

AegisLab AV Signature
Troj.FakeAV.W32.Agent
20.00%

McAfee
Artemis!21773ACB5B0F
20.00%

Rising Antivirus
PE:Trojan.Win32.Sprejy.a!1075357081
20.00%

herdProtect (fuzzy)
a variant of 9ffd66bafe0ac545f5d46d45800551db810f2013
20.00%

The domain tools.safezone.cc has been seen to resolve to the following 3 IP addresses.

cf-173-245-60-143.cloudflare.com
December 6, 2014

cf-173-245-61-143.cloudflare.com
December 6, 2014

cf539791.freehost.com.ua
April 6, 2014

File downloads found at URLs served by tools.safezone.cc.

2 / 68      (PUP)
http://tools.safezone.cc/glax24/.../SecurityCheck.exe  (afa67ca98888aac2d1b453afd5fb0347)

5 / 68      (PUP)
http://tools.safezone.cc/glax24/.../SecurityCheck.exe  (67e356ed298c3b22b283b6a0ca5af7cf)

5 / 68      (PUP)
http://tools.safezone.cc/glax24/.../SecurityCheck.exe  (21773acb5b0f5ec91434df59293b9a65)

5 / 68      (PUP)
http://tools.safezone.cc/glax24/.../SecurityCheck.exe  (41781ae2daef6f40bec311ef4ef5bdda)

5 / 68      (PUP)
http://tools.safezone.cc/glax24/.../SecurityCheck.exe  (4a2403bcefb0adf1c3cc1be829ba2e35)

URL:
http://tools.safezone.cc/

Web server:
nginx/1.2.1

Remove Malware from tools.safezone.cc - Powered by Reason Core Security