www.antivirusfrancais.com

BERNEX APLICACIONES SL

Domain Information

The domain www.antivirusfrancais.com registered by BERNEX APLICACIONES SL was initially registered in June of 2014 through SOLUCIONES CORPORATIVAS IP,SLU. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Madrid, Madrid within Spain which resides on the RIPE Network Coordination Centre network.
Registrar:
SOLUCIONES CORPORATIVAS IP, SL

Server location:
Madrid, Spain (ES)

Create date:
Saturday, June 28, 2014

Expires date:
Tuesday, June 28, 2016

Updated date:
Thursday, May 28, 2015

ASN:
AS57286 ASGIGAS GIGAS HOSTING S.L.,ES

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.BERNEXAPLICACIONESSL.DD, PUP.BERNEXAPLICACIONES.Installer (M), Threat.Win.Reputation.IMP
100.00%

AVG
Generic
57.14%

Malwarebytes
PUP.SmsPay, PUP.Optional.Installcore
42.86%

K7 AntiVirus
JokeProgram , Unwanted-Program
42.86%

VIPRE Antivirus
Trojan.Win32.Generic
28.57%

Trend Micro House Call
Suspicious_GEN.F47V1027, Suspicious_GEN.F47V1024
28.57%

McAfee
Artemis!6EE99A48AA4C, Artemis!B675039A3F3D
28.57%

ESET NOD32
NSIS/Hoax.ArchSMS
28.57%

Sophos
Generic PUA HD
14.29%

Baidu Antivirus
Trojan.NSIS.ArchSMS
14.29%

ESET NOD32
NSIS/Hoax.ArchSMS.W application
14.29%

The domain www.antivirusfrancais.com has been seen to resolve to the following 3 IP addresses.

July 2, 2016

188-165-132-183.kimsufi.com
February 13, 2016

mail.phpriot.com
May 4, 2015

File downloads found at URLs served by www.antivirusfrancais.com.

1 / 68      (Adware)

4 / 68      (Adware)
http://www.antivirusfrancais.com/.../telechargeravast.php  (avast_antivirus_2014_en_setup.exe)

1 / 68      (Adware)

2 / 68      (Malware)
http://www.antivirusfrancais.com/.../telechargeravast.php  (avast_antivirus_2014_fr_setup.exe)

4 / 68      (Adware)
http://www.antivirusfrancais.com/.../telechargeravira.php  (avira_antivirus_2014_en_setup.exe)

10 / 68    (Adware)
http://www.antivirusfrancais.com/.../telechargeravast.php  (avast_antivirus_2014_fr_setup.exe)

6 / 68      (Adware)
http://www.antivirusfrancais.com/.../telechargeravast.php  (avast_antivirus_2014_fr_setup.exe)

The following 26 files have been seen to comunicate with www.antivirusfrancais.com in live environments.

 
Latest 20 of 26 files

URL:
http://www.antivirusfrancais.com/

Title:
“Home | Australia VISA ETA”

Web server:
Apache/2.4.7 (Ubuntu) (PHP/5.5.9-1ubuntu4.14)

30 of 37 related domains