welovecoupon.eu

NOT DISCLOSED!  (Proxy Registrant)

Domain Information

The domain welovecoupon.eu is registered by proxy through Internet.bs Corp.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Remove Malware from welovecoupon.eu - Powered by Reason Core Security
Registrar:
Internet.bs Corp.

Server location:
Northern Ireland, United Kingdom (GB)

Scanner detections:
Detections  (95% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer.AA, Adware.WebPick.Installer.I, Adware.WebPick.Installer.V, Adware.WebPick.Installer.R, Adware.WebPick.Installer.?, Adware.WebPick.Installer.F, Adware.WebPick.Installer.E, Adware.WebPick.Installer.T, PUP.Installer.Adknowledge, DownloadManager.Bundler.Air Software, Adware.AdInjector.Installer, Adware.StanislavKabin.Installer (M), Adware.WebPick.Installer (M), Adware.ClearAskyInstaller.Installer (M), Adware.AppReadySoftware.Installer (M), PUP.Outbrowse.Bundler (M), PUP.Adknowledge.FUSIONINSTALLER.Installer (M)
97.62%

McAfee
Artemis!E013B625F5AE, PUP-FHQ, PUP-FNL, Program.PUP-FHQ, Program.IBryte-FSO, Trojan.Artemis!757FB24A0964, Program.PUP-FNL
57.14%

Rising Antivirus
Trojan.Script.Agent.ac, PE:Trojan.AntiFW!6.1983, PE:Trojan.AntiFW!6.17F7, PE:Trojan.AntiFW!6.15EE, PE:Trojan.AntiFW!6.1950
57.14%

Kaspersky
Trojan.Win32.AntiFW, not-a-virus:AdWare.Win32.MultiPlug, not-a-virus:AdWare.Win32.iBryte, not-a-virus:AdWare.Win32.AirAdInstaller
57.14%

Malwarebytes
PUP.Optional.InstalleRex, PUP.Optional.Installrex, PUP.Optional.ItsMyApp, PUP.Optional.OptimunInstaller, PUP.Optional.AirAdInstaller
57.14%

K7 AntiVirus
Unwanted-Program
57.14%

NANO AntiVirus
Riskware.Win32.InfoLeak.cvgqot, Riskware.Win32.IBryte.desauy, Riskware.Win32.AirAdInstaller.dlqckn, Riskware.Win32.Downware.cvftvo
57.14%

Agnitum Outpost
Trojan.AntiFW, PUA.InstalleRex, PUA.Agent, PUA.AirAd, PUA.TDownloader.A
57.14%

ESET NOD32
Win32/InstalleRex.M potentially unwanted application, Win32/Adware.iBryte.BR application, Win32/AirAdInstaller.E potentially unwanted application
54.76%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic, Threat.4778314, Iminent, Installerex/WebPick
54.76%

Dr.Web
Trojan.WebPick.2533, Trojan.WebPick.2818, Threat.Undefined, Trojan.iBryte.47, Adware.Downware.9532, Trojan.WebPick.2579
54.76%

avast!
Win32:InstalleRex-AZ [PUP], Win32:InstalleRex-DL [PUP], Win32:InstalleRex-CJ [PUP], Win32:PUP-gen [PUP], Win32:InstalleRex-DT [PUP]
54.76%

K7 Gateway Antivirus
Unwanted-Program , Trojan
54.76%

Comodo Security
Application.Win32.InstalleRex.KG, Application.Win32.AgentCV.HWYE, Packed.Win32.MUPX.Gen, Application.Win32.iBryte.WRP
54.76%

McAfee Web Gateway
BehavesLike.Win32.Downloader.fc, IBryte-FRT, BehavesLike.Win32.Downloader.tc, BehavesLike.Win32.StartPage.fc, PUP-FNL, Generic-FAIN!F3F4D6BF6FB9
54.76%

The domain welovecoupon.eu has been seen to resolve to the following 16 IP addresses.

January 3, 2016

192.193.28.185.gransy.com
October 12, 2015

June 18, 2015

193.193.28.185.gransy.com
June 18, 2015

unallocated.barefruit.co.uk
May 2, 2015

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
January 1, 2015

ec2-54-68-226-215.us-west-2.compute.amazonaws.com
September 22, 2014

ec2-54-68-105-209.us-west-2.compute.amazonaws.com
September 11, 2014

ec2-54-186-53-99.us-west-2.compute.amazonaws.com
August 28, 2014

ec2-54-191-153-135.us-west-2.compute.amazonaws.com
August 24, 2014

ec2-54-191-209-50.us-west-2.compute.amazonaws.com
August 19, 2014

ec2-54-191-186-103.us-west-2.compute.amazonaws.com
July 31, 2014

ec2-54-191-92-197.us-west-2.compute.amazonaws.com
July 7, 2014

ec2-54-201-84-24.us-west-2.compute.amazonaws.com
July 3, 2014

ec2-54-187-76-32.us-west-2.compute.amazonaws.com
June 13, 2014

ec2-54-186-255-26.us-west-2.compute.amazonaws.com
April 4, 2014

File downloads found at URLs served by welovecoupon.eu.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://welovecoupon.eu/v2109?installer_file_name=????????????????1  (ดาวน์โหลดไฟล์ที่1.exe)

1 / 68      (Adware)
http://welovecoupon.eu/.../span>  (download _span class=-dlfilesize-_(44.98 kb)__span_.exe)

1 / 68      (Adware)

38 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

30 / 68    (Adware)

1 / 68      (Adware)

36 / 68    (Adware)

31 / 68    (Adware)

35 / 68    (Adware)

30 / 68    (Adware)

34 / 68    (Adware)

35 / 68    (Adware)

34 / 68    (Adware)

36 / 68    (Adware)

30 / 68    (Adware)

 
Latest 30 of 135 download URLs

The following 145 files have been seen to comunicate with welovecoupon.eu in live environments.

 
Latest 20 of 145 files

URL:
http://welovecoupon.eu/

Google Analytics:
UA-48689684

Title:
“welovecoupon.eu”

Web server:
ZeroPark-Traffic

30 of 247 related domains

Remove Malware from welovecoupon.eu - Powered by Reason Core Security