www-squid.cluster11.fb-hosting-apps.com

PERFECT PRIVACY, LLC  (Proxy Registrant)

Domain Information

The domain www-squid.cluster11.fb-hosting-apps.com is registered by proxy through DOMAIN STOPOVER LLC and was originally registered in March of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network.
Registrar:
DOMAIN STOPOVER LLC

Server location:
Dublin City, Ireland (IE)

Create date:
Wednesday, March 23, 2016

Expires date:
Thursday, March 23, 2017

Updated date:
Wednesday, March 23, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (93% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Ukra2006.u, PUP.Installer.Ukra2006.?, PUP.Installer.Ukra2006.w, PUP.Installer.Ukra2006.AA, PUP.Installer.Ukra2006.y, Threat.Win.Reputation.IMP, Adware.Amonetize.Installer.Installer.Meta (M), PUP.Amonetize.Ukra2006.Bundler (M), PUP.Amonetize (M)
97.73%

Malwarebytes
PUP.Optional.Amonetize
54.55%

ESET NOD32
Win32/Amonetize.BN (variant), Win32/Amonetize.BO (variant), Win32/Amonetize.BR (variant), Win32/Amonetize.BS (variant), Win32/Amonetize.BK (variant)
52.27%

AVG
Generic_r, Downloader.Generic14, Ukra
52.27%

Sophos
Amonetize, Generic PUA CL, Generic PUA KG, Generic PUA BB, Generic PUA BE, Generic PUA ME
50.00%

AhnLab V3 Security
PUP/Win32.Amonetize, Win32/Virut.F
47.73%

Baidu Antivirus
Adware.Win32.Amonetize, PUA.Win32.Amonetize
47.73%

Agnitum Outpost
PUA.Amonetize, Win32.Virut.AB.Gen
43.18%

McAfee
PUP-Amonetize, Artemis!CE357453C05F, W32/Virut.n.gen, Artemis!DD2FDC017F65, Artemis!9CCC071F93A4, Artemis!2C5B9FBE426D, PUP-FQT, Artemis!D144B373A76E, RDN/Generic.dx!df3
40.91%

NANO AntiVirus
Riskware.Win32.Amonetize.delxsa, Riskware.Win32.Amonetize.dffaha, Virus.Win32.Virut.hpeg, Riskware.Win32.Downware.dfqeij
40.91%

Avira AntiVirus
Adware/Amonetize.tzw, ADWARE/Adware.Gen, Adware/Amonetize.tzv, ADWARE/Adware.Gen4, ADWARE/Adware.Gen2
36.36%

K7 AntiVirus
Unwanted-Program , Virus , Trojan
36.36%

Panda Antivirus
Trj/Genetic.gen, W32/Sality.AO
34.09%

Dr.Web
Adware.Downware.8379, Win32.Virut.56, Adware.Downware.8564, Adware.Downware.8618, Adware.Downware.8655, Adware.Downware.8706
34.09%

Fortinet FortiGate
Riskware/Amonetize, W32/FakeAV.RQ!tr, Adware/Amonetize
34.09%

The domain www-squid.cluster11.fb-hosting-apps.com has been seen to resolve to the following 6 IP addresses.

July 17, 2016

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
May 31, 2016

April 4, 2016

ns1.ibspark.com
February 8, 2016

September 1, 2014

September 1, 2014

File downloads found at URLs served by www-squid.cluster11.fb-hosting-apps.com.

 
Latest 30 of 277 download URLs

The following 348 files have been seen to comunicate with www-squid.cluster11.fb-hosting-apps.com in live environments.

 
Latest 20 of 373 files

URL:
http://www-squid.cluster11.fb-hosting-apps.com/

Title:
“fb-hosting-apps.com”

Web server:
nginx