www-vanilla1.fb-hosting-apps.com

PERFECT PRIVACY, LLC  (Proxy Registrant)

Domain Information

The domain www-vanilla1.fb-hosting-apps.com is registered by proxy through DOMAIN STOPOVER LLC and was originally registered in March of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network.
Registrar:
DOMAIN STOPOVER LLC

Server location:
Dublin City, Ireland (IE)

Create date:
Wednesday, March 23, 2016

Expires date:
Thursday, March 23, 2017

Updated date:
Wednesday, March 23, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ShetefSolutionsConsulting1998.y, PUP.Installer.ShetefSolutionsConsulting1998.?, PUP.Installer.ShetefSolutionsConsulting1998.p, PUP.Amonetize.ShetefSolutionsConsulting1998.Bundler (M), PUP.Amonetize.ShetefSo.Bundler (M)
100.00%

Sophos
Amonetize, Generic PUA KF, Generic PUA OD, Generic PUA AM, Generic PUA MC, Generic PUA EE, Generic PUA OB, Generic PUA NB
93.33%

Avira AntiVirus
Adware/Amonetize.519376.14, ADWARE/Adware.Gen4, Adware/Amonetize.575168.47, TR/Crypt.ZPACK.Gen2
93.33%

ESET NOD32
Win32/Amonetize.BW (variant), Win32/Amonetize.BY (variant), Win32/Amonetize.CH (variant), Win32/Amonetize.CK (variant), Win32/Amonetize.CS (variant)
90.00%

Malwarebytes
PUP.Optional.Amonetize, PUP.Optional.Monetizer
83.33%

McAfee
Artemis!00007E9365A6, Artemis!611F9296BC99, Artemis!5B00B3156F9C, Artemis!F0261D144A88, Artemis!7E6C890D68D1, Artemis!96D2F46B27F4, Artemis!0175C95AB9CE, Artemis!0344C816755A, Artemis!D30B2CBB21CD, Artemis!C6AE952BA480, Artemis!91963B7861C3
83.33%

Fortinet FortiGate
Adware/Amonetize, Riskware/Amonetize, W32/Virut.CE
83.33%

AhnLab V3 Security
PUP/Win32.Amonetize
73.33%

AVG
Ukra, Generic, Downloader.Generic14
73.33%

Dr.Web
Adware.Downware.8868, Adware.Downware.8876, Adware.Downware.8996, Trojan.Amonetize.341, Trojan.Adfltnet.70
60.00%

Agnitum Outpost
PUA.Amonetize
56.67%

Bitdefender
Gen:Variant.Graftor.161610, Gen:Variant.Adware.Graftor.161610, Gen:Variant.Application.Jaik.4831, Win32.Virtob.Gen.12, Trojan.GenericKD.2067331
53.33%

F-Secure
Gen:Variant.Graftor.161610, Gen:Variant.Adware.Graftor.161610, Gen:Variant.Application.Jaik, Win32.Virtob.Gen.12, Trojan.GenericKD.2067331
53.33%

G Data
Gen:Variant.Graftor.161610, Gen:Variant.Adware.Graftor.161610, Gen:Variant.Application.Jaik.4831, Win32.Virtob.Gen.12, Trojan.GenericKD.2067331
53.33%

MicroWorld eScan
Gen:Variant.Graftor.161218, Gen:Variant.Application.Jaik.4831, Gen:Variant.Adware.Graftor.161610, Win32.Virtob.Gen.12, Trojan.GenericKD.2067331, Gen:Variant.Application.Bundler.Amonetize.18
50.00%

The domain www-vanilla1.fb-hosting-apps.com has been seen to resolve to the following 4 IP addresses.

April 13, 2016

ns1.ibspark.com
February 9, 2016

November 1, 2014

November 1, 2014

File downloads found at URLs served by www-vanilla1.fb-hosting-apps.com.

 
Latest 30 of 42 download URLs

The following 142 files have been seen to comunicate with www-vanilla1.fb-hosting-apps.com in live environments.

 
Latest 20 of 154 files

URL:
http://www-vanilla1.fb-hosting-apps.com/

Title:
“fb-hosting-apps.com”

Web server:
nginx