wanktubevideos.com

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain wanktubevideos.com is registered by proxy through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM and was originally registered in May of 2012. Currently this domain has been known to host various forms of malware. The hosted servers are located in Dover, North Carolina within the United States which resides on the SoftLayer Technologies Inc. network.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
North Carolina, United States (US)

Create date:
Sunday, May 06, 2012

Expires date:
Friday, May 06, 2016

Updated date:
Thursday, May 07, 2015

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.

Scanner detections:
Malware distribution  (71% detected)

Scan engine
Details
Detections

VIPRE Antivirus
Trojan.Win32.Generic
85.71%

McAfee
RDN/Generic.dx!cs3, RDN/Generic.dx!cst, Artemis!C2B7E122F495, Artemis!54C5263EF203, Artemis!BAB09D665364
71.43%

Norman
Suspicious_Gen4.FBKKT, Suspicious_Gen4.FMADJ, Suspicious_Gen4.FJISI, Suspicious_Gen4.EPSYM
71.43%

Trend Micro House Call
TROJ_GEN.R0CBC0OJE13, TROJ_GEN.F47V0924, Suspicious_GEN.F47V0816, TROJ_GEN.R047B01JT14, TROJ_SPNR.15IA13
71.43%

avast!
Win32:Malware-gen, JS:Includer-AIH [Trj], Win32:AdvertBHO-A [Trj]
71.43%

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader, Trojan.Agent/Gen-VBInject, Trojan.Agent/Gen-Clicker, Trojan.Agent/Gen-FakeDefender
71.43%

Avira AntiVirus
TR/Downloader.Gen7, TR/BHO.cmco.2
71.43%

Sophos
Mal/Generic-S
71.43%

Baidu Antivirus
Trojan.JS.TrojanClicker, Trojan.Script.Generic, Trojan.JS.Clicker, Trojan.Win32.BHO
71.43%

ESET NOD32
JS/TrojanClicker.Agent.NFD, JS/TrojanClicker.Agent.NEX, JS/TrojanClicker.Agent.NFB, Win32/Adware.BHO.NKY
71.43%

Qihoo 360 Security
Win32/Trojan.Script.ed4, Script/Trojan.Clicker.964, HEUR/Malware.QVM06.Gen, Win32/Trojan.Downloader.8ec, Win32/Trojan.Clicker.a3b
71.43%

K7 Gateway Antivirus
Spyware , Riskware
57.14%

K7 AntiVirus
Spyware , Riskware
57.14%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious-PKR.G, BehavesLike.Win32.StartPage.qc
57.14%

Kingsoft AntiVirus
Win32.Troj.ADClicker.(kcloud), Win32.Troj.Generic_a.a.(kcloud), Win32.Troj.Generic.a.(kcloud), Win32.Troj.BHO.cm.(kcloud)
57.14%

The domain wanktubevideos.com has been seen to resolve to the following 2 IP addresses.

209-99-40-223.fwd.datafoundry.com
May 15, 2015

50.23.150.25-static.reverse.softlayer.com
December 22, 2013

File downloads found at URLs served by wanktubevideos.com.

 
Latest 30 of 31 download URLs

The following 26 files have been seen to comunicate with wanktubevideos.com in live environments.

 
Latest 20 of 30 files

URL:
http://wanktubevideos.com/

Title:
“Wanktubevideos.com”

Web server:
Apache