ttb.proplayersetup.com

chen wenjie

Domain Information

The domain ttb.proplayersetup.com registered by chen wenjie was initially registered in October of 2014 through SOLUCIONES CORPORATIVAS IP,SLU. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Vitoria-Gasteiz, Pais Vasco within Spain which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Pais Vasco, Spain (ES)

Create date:
Saturday, October 4, 2014

Expires date:
Tuesday, October 4, 2016

Updated date:
Monday, September 14, 2015

ASN:
AS57910 SCIP-AS Soluciones Corporativas IP, SL,ES

Root domain:

Google Safe Browsing:
malware

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.TuguuSL.M, PUP.Installer.LunacomInteractive.M, Threat.Win.Reputation.IMP, PUP.Tuguu.Bundler (M), PUP.Tuguu.LunacomInteractive.Bundler (M), PUP.Tuguu.TuguuU.Bundler (M), PUP.Tuguu.TuguuIsrael.Bundler (M), PUP.Tuguu.Awimba.Bundler (M), PUP.Tuguu.Payments.Bundler (M), PUP.Tuguu.LunacomI.Bundler (M), PUP.Tuguu (M)
100.00%

VIPRE Antivirus
DomaIQ, Threat.4783235, Threat.4783262
25.00%

avast!
Installer-AE [PUP], PUP-gen [PUP], DomaIQ-AD [PUP], Win32:SoftPulse-AL [PUP]
25.00%

Dr.Web
Trojan.Packed.24553, Trojan.Domaiq.1
25.00%

AVG
Downloader.Small, Adware AdLoad.B, Adware Generic_c.TY, Adware DomaIQ.BN
25.00%

McAfee
Adware-DomaIQ, Artemis!EE65979880B9, Softpulse.a, Artemis!ADC099CCC3F4
16.67%

Malwarebytes
PUP.Optional.DomaIQ, PUP.Optional.BundleInstaller.A
16.67%

K7 AntiVirus
Trojan , Unwanted-Program
16.67%

NANO AntiVirus
Trojan.Win32.DomaIQ.csdqll, Trojan.Win32.DomaIQ.csqtgn, Riskware.Win32.SoftPulse.dgqttv, Riskware.Win32.DomaIQ.cummfj
16.67%

Agnitum Outpost
PUA.DomaIQ, Riskware.Agent
16.67%

Sophos
DomainIQ pay-per install, Generic PUA IG, SoftPulse, Generic PUA CI
16.67%

Avira AntiVirus
APPL/DomaIQ.Gen7, TR/Dropper.Gen
16.67%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, AdWare.MSIL.DomaIQ, BScope.Adware.Softpulse
16.67%

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ, not-a-virus:AdWare.Win32.Lollipop, not-a-virus:Downloader.Win32.DriverUpd, not-a-virus:HEUR:AdWare.MSIL.DomaIQ
16.67%

Emsisoft Anti-Malware
Adware.DomaIQ.T, Application.Bundler.DomaIQ.Q
16.67%

The domain ttb.proplayersetup.com has been seen to resolve to the following 5 IP addresses.

lb-182-207.above.com
May 17, 2016

lb-182-243.above.com
May 3, 2015

December 9, 2014

www.renewyourexpireddomain.com
August 10, 2014

ec2-50-112-177-75.us-west-2.compute.amazonaws.com
May 31, 2014

File downloads found at URLs served by ttb.proplayersetup.com.

The following 23 files have been seen to comunicate with ttb.proplayersetup.com in live environments.

 
Latest 20 of 37 files

URL:
http://ttb.proplayersetup.com/

Title:
“proplayersetup.com”

Title (8/10/2014):
“ ”

Title (5/3/2015):
“proplayersetup.com - This website is for sale! - proplayersetup Resources and Information.”

Web server:
Apache