ublk2014date.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain ublk2014date.com is registered by proxy through ENOM, INC. and was originally registered in March of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Orange, California within the United States which resides on the Krypt Technologies network.
Registrar:
ENOM, INC.

Server location:
California, United States (US)

Create date:
Tuesday, March 18, 2014

Expires date:
Wednesday, March 18, 2015

Updated date:
Tuesday, March 18, 2014

ASN:
AS35908 VPLSNET - Krypt Technologies

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.PaymentsInteractiveSL.E, PUP.Tuguu.PaymentsInteractive.Bundler (M), PUP.Tuguu.Payments.Bundler (M), PUP.Tuugu.Bundler.Meta (M), Threat.Win.Reputation.IMP, PUP.Tuguu (M)
97.73%

McAfee
RDN/Generic PUP.x!b2z, RDN/Generic.bfr!gf, Adware-DomaIQ!F6CB534A58DC
11.36%

Malwarebytes
PUP.Optional.Domalq, PUP.Optional.DomalQ, PUP.Optional.BundleInstaller.A
11.36%

VIPRE Antivirus
Trojan.Win32.Generic, DomaIQ
11.36%

K7 Gateway Antivirus
Unwanted-Program
11.36%

Agnitum Outpost
PUA.DomaIQ, PUA.Lollipop
11.36%

Sophos
DomainIQ pay-per install
11.36%

Dr.Web
Trojan.Packed.142, Trojan.DownLoader11.3971, Trojan.DownLoader9.21779
11.36%

Avira AntiVirus
APPL/DomaIQ.Gen
11.36%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious.H, RDN/Generic.bfr!gf
11.36%

Jiangmin
Pack.Mal.AntiVM, AdWare/MSIL.aij
11.36%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/Win32.Lollipop, GrayWare[AdWare:not-a-virus]/MSIL.DomaIQ
11.36%

ESET NOD32
Win32/DomaIQ.BB (variant), Win32/DomaIQ.AZ (variant)
11.36%

IKARUS anti.virus
AdWare.DomaIQ
11.36%

AVG
DomaIQ_r.G, Skodna.Bundle_r.Y
11.36%

The domain ublk2014date.com has been seen to resolve to the following IP address.

comfort72.thebestdeal1b.com
March 20, 2014

File downloads found at URLs served by ublk2014date.com.

1 / 68      (Adware)
http://ublk2014date.com/.../Java.exe  (441e122ba7eaa6d1401ef138422b68a1)

URL:
http://ublk2014date.com/

Web server:
nginx