transferbarrweb.com

Whois Privacy Protection Service, Inc.  (Proxy Registrant)

Domain Information

The domain transferbarrweb.com is registered by proxy through NAME.COM, INC. and was originally registered in February of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Kirkland, Washington within the United States which resides on the eNom, Incorporated network.
Registrar:
NAME.COM, INC.

Server location:
Washington, United States (US)

Create date:
Tuesday, February 25, 2014

Expires date:
Saturday, February 25, 2017

Updated date:
Tuesday, March 22, 2016

ASN:
AS21740 ENOMAS1 - eNom, Incorporated,US

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer.HH, Adware.WebPick.Installer.FF, Adware.WebPick.Installer.?, PUP.AlexeyKurilenko.o, PUP.AlexeyKurilenko.FF, PUP.AlexeyKurilenko.CC, PUP.AlexeyKurilenko.t, PUP.StanislavKabin.FF, Adware.WebPick.Installer (M), Adware.ShowAppIt.Installer (M), PUP.WebPick.AlexeyKu (M), Adware (M)
88.24%

Dr.Web
Trojan.WebPick.2452, Threat.Undefined, Trojan.Crossrider.28215, Trojan.Crossrider.37867
58.82%

AVG
Generic, Adware Generic5, Adware Generic5.BENU, Adware Generic_r.VD
58.82%

McAfee
PUP-FHQ!028CCF3DED34, Trojan.Artemis!BB57FC5359EE, MultiPlug-FRO
52.94%

Malwarebytes
PUP.Optional.InstalleRex, PUP.Optional.DownloaderSS, PUP.Optional.MultiPlug
52.94%

NANO AntiVirus
Riskware.Win32.InfoLeak.cvgqot, Riskware.Win32.MultiPlug.ddsvpv, Riskware.Win32.MultiPlug.dfjscb
52.94%

Comodo Security
Application.Win32.InstalleRex.KG, Application.Win32.GreenApp.RR, Application.Win32.Multiplug.CT
52.94%

Avira AntiVirus
Adware/InstallRex.ode, TR/Kazy.324119.29, Adware/MultiPlug.aob, ADWARE/MultiPlug.Gen7
52.94%

Kaspersky
Trojan.Win32.AntiFW, not-a-virus:AdWare.Win32.MultiPlug
47.06%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696
47.06%

Sophos
InstallRex, MultiPlug
47.06%

ESET NOD32
Win32/InstalleRex, Win32/AdWare.MultiPlug.BF (variant), Win32/AdWare.MultiPlug.CT (variant)
41.18%

IKARUS anti.virus
PUA.BInstaller, AdWare.SaveNet
41.18%

herdProtect (fuzzy)
a variant of b23b661c23814dc09f7c2b5fd50eef4000726362, a variant of bab1326746587faec9a2d961e1ea34803ca5477c, a variant of 8d45b0582f0c6cc9dfb49e56093f82d44cbc68e8
41.18%

Agnitum Outpost
Trojan.AntiFW, PUA.MultiPlug
35.29%

The domain transferbarrweb.com has been seen to resolve to the following 13 IP addresses.

.
September 13, 2016

August 13, 2016

June 6, 2016

April 11, 2016

April 8, 2016

rc2.sjl01.dmtracker.com
April 4, 2016

ec2-52-27-166-51.us-west-2.compute.amazonaws.com
January 28, 2016

ec2-54-68-85-18.us-west-2.compute.amazonaws.com
November 10, 2014

ec2-54-68-142-187.us-west-2.compute.amazonaws.com
November 10, 2014

ec2-54-191-209-50.us-west-2.compute.amazonaws.com
August 19, 2014

ec2-54-191-186-103.us-west-2.compute.amazonaws.com
July 31, 2014

ec2-54-201-84-24.us-west-2.compute.amazonaws.com
July 3, 2014

ec2-54-186-255-26.us-west-2.compute.amazonaws.com
May 15, 2014

File downloads found at URLs served by transferbarrweb.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

17 / 68    (PUP)

19 / 68    (Adware)

19 / 68    (Adware)

The following 36 files have been seen to comunicate with transferbarrweb.com in live environments.

 
Latest 20 of 49 files

URL:
http://transferbarrweb.com/

Google Analytics:
UA-2249740

Title:
“Transferbarrweb.com”

Description:
“Find Cash Advance, Debt Consolidation and more at Transferbarrweb.com. Get the best of Insurance or Free Credit Report, browse our section on Cell Phones or learn about Life Insurance. Transferbarrweb.com is the site for Cash Advance.”

Web server:
Apache

30 of 685 related domains