ws4.fb-hosting-apps.com

PERFECT PRIVACY, LLC  (Proxy Registrant)

Domain Information

The domain ws4.fb-hosting-apps.com is registered by proxy through DOMAIN STOPOVER LLC and was originally registered in March of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
DOMAIN STOPOVER LLC

Server location:
Arizona, United States (US)

Create date:
Wednesday, March 23, 2016

Expires date:
Thursday, March 23, 2017

Updated date:
Wednesday, March 23, 2016

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Scanner detections:
Detections  (88% detected)

Scan engine
Details
Detections

Avira AntiVirus
ADWARE/Adware.Gen2
93.75%

Sophos
Amonetize
93.75%

Baidu Antivirus
Adware.Win32.Amonetize
87.50%

ESET NOD32
Win32/Amonetize.AJ (variant)
87.50%

AhnLab V3 Security
PUP/Win32.Amonetiz
81.25%

Rising Antivirus
PE:Malware.Adware!6.17D8, PE:Malware.Adware!6.1890
81.25%

McAfee
Artemis!27C1F7FD3B2B, Artemis!8DEAE6AE80CC, Artemis!CD00420B9BEC, Artemis!03E9FD57F865, Artemis!AD207E79A06A, Artemis!06580B6B0AD9, Artemis!D398895D0274, Artemis!78AA7F4428FB, Artemis!8565485750B9, Artemis!5A7FFC311F44, Artemis!9309211174A0
75.00%

Malwarebytes
PUP.Optional.Amonetize.A
75.00%

avast!
Win32:Amonetize-AK [PUP], Win32:Amonetize-AM [PUP], Win32:Amonetize-AX [PUP]
75.00%

Dr.Web
Adware.Downware.2467, Adware.Downware.3081
75.00%

AVG
Generic_r
75.00%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize
68.75%

Reason Heuristics
Threat.Win.Reputation.IMP, PUP.Win.Reputation
62.50%

Qihoo 360 Security
Win32/Virus.Adware.932, Win32/Trojan.Multi.daf
50.00%

NANO AntiVirus
Riskware.Win32.Amonetize.cwdsjp, Riskware.Win32.Amonetize.cwghla, Riskware.Win32.Amonetize.cwjksk, Riskware.Win32.Amonetize.cwhavf
37.50%

The domain ws4.fb-hosting-apps.com has been seen to resolve to the following 5 IP addresses.

April 5, 2016

September 2, 2014

September 2, 2014

(CloudFlare)
May 1, 2014

(CloudFlare)
May 1, 2014

File downloads found at URLs served by ws4.fb-hosting-apps.com.

 
Latest 30 of 38 download URLs

URL:
http://ws4.fb-hosting-apps.com/

Title:
“fb-hosting-apps.com”

Web server:
nginx