ttb.proplayersetup.com

chen wenjie

Domain Information

The domain ttb.proplayersetup.com registered by chen wenjie was initially registered in October of 2014 through SOLUCIONES CORPORATIVAS IP,SLU. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Vitoria-Gasteiz, Pais Vasco within Spain which resides on the RIPE Network Coordination Centre network.
Remove Malware from ttb.proplayersetup.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Pais Vasco, Spain (ES)

Create date:
Saturday, October 04, 2014

Expires date:
Tuesday, October 04, 2016

Updated date:
Monday, September 14, 2015

ASN:
AS57910 SCIP-AS Soluciones Corporativas IP, SL,ES

Root domain:

Google Safe Browsing:
malware

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.TuguuSL.M, PUP.Installer.LunacomInteractive.M, Threat.Win.Reputation.IMP, PUP.Tuguu.Bundler (M), PUP.Tuguu.LunacomInteractive.Bundler (M)
100.00%

VIPRE Antivirus
DomaIQ, Threat.4783235, Threat.4783262
75.00%

avast!
Installer-AE [PUP], PUP-gen [PUP], DomaIQ-AD [PUP], Win32:SoftPulse-AL [PUP]
75.00%

Dr.Web
Trojan.Packed.24553, Trojan.Domaiq.1
75.00%

AVG
Downloader.Small, Adware AdLoad.B, Adware Generic_c.TY, Adware DomaIQ.BN
75.00%

McAfee
Adware-DomaIQ, Artemis!EE65979880B9, Softpulse.a, Artemis!ADC099CCC3F4
50.00%

Malwarebytes
PUP.Optional.DomaIQ, PUP.Optional.BundleInstaller.A
50.00%

K7 AntiVirus
Trojan , Unwanted-Program
50.00%

K7 Gateway Antivirus
Trojan , Unwanted-Program
50.00%

NANO AntiVirus
Trojan.Win32.DomaIQ.csdqll, Trojan.Win32.DomaIQ.csqtgn, Riskware.Win32.SoftPulse.dgqttv, Riskware.Win32.DomaIQ.cummfj
50.00%

Agnitum Outpost
PUA.DomaIQ, Riskware.Agent
50.00%

Sophos
DomainIQ pay-per install, Generic PUA IG, SoftPulse, Generic PUA CI
50.00%

Avira AntiVirus
APPL/DomaIQ.Gen7, TR/Dropper.Gen
50.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, AdWare.MSIL.DomaIQ, BScope.Adware.Softpulse
50.00%

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ, not-a-virus:AdWare.Win32.Lollipop, not-a-virus:Downloader.Win32.DriverUpd, not-a-virus:HEUR:AdWare.MSIL.DomaIQ
50.00%

The domain ttb.proplayersetup.com has been seen to resolve to the following 4 IP addresses.

lb-182-243.above.com
May 3, 2015

December 9, 2014

www.renewyourexpireddomain.com
August 10, 2014

ec2-50-112-177-75.us-west-2.compute.amazonaws.com
May 31, 2014

File downloads found at URLs served by ttb.proplayersetup.com.

The following file have been seen to comunicate with ttb.proplayersetup.com in live environments.

URL:
http://ttb.proplayersetup.com/

Web server:
Apache (PHP/5.4.45-0+deb7u2)

Remove Malware from ttb.proplayersetup.com - Powered by Reason Core Security