www.appfael.com

Moniker Privacy Services  (Proxy Registrant)

Domain Information

The domain www.appfael.com is registered by proxy through Moniker Online Services and was originally registered in July of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the SoftLayer Technologies Inc. network.
Registrar:
Moniker Online Services

Server location:
Texas, United States (US)

Create date:
Tuesday, July 1, 2014

Expires date:
Wednesday, July 1, 2015

Updated date:
Tuesday, July 1, 2014

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.R2D2TechSoftware.T, PUP.Performersoft.PurpleTechSoftware.Bundler (M), PUP.Performersoft.PurpleTe.Bundler (M), PUP.Performersoft.GiraffeT.Bundler (M), PUP.Performersoft (M)
100.00%

Malwarebytes
PUP.Optional.InstallBrain.A, PUP.Optional.CodecPerformer.A
21.43%

Dr.Web
Adware.Downware.6211, Adware.Downware.2543, Adware.Downware.8001, Trojan.Packed.28512
21.43%

VIPRE Antivirus
InstallBrain, Threat.4759033
21.43%

AhnLab V3 Security
PUP/Win32.InstallBrain
21.43%

AVG
Adware InstallBrain, Adware InstallBrain.S
21.43%

Sophos
InstallBrain, PUA.InstallBrain, PUA 'InstallBrain'
21.43%

Comodo Security
Application.Win32.InstallBrain.BF
21.43%

MicroWorld eScan
Gen:Variant.Jaik.1231, Adware.InstallBrain.E
21.43%

Bitdefender
Gen:Variant.Jaik.1231, Adware.InstallBrain.E
21.43%

Emsisoft Anti-Malware
Gen:Variant.Jaik.1231, Gen:Variant.Jaik.2984, Adware.InstallBrain
21.43%

G Data
Win32.Application.InstallBrain, Gen:Variant.Jaik.1231
21.43%

Agnitum Outpost
PUA.InstallBrain
21.43%

NANO AntiVirus
Trojan.Win32.DownLoader11.dbedcj, Riskware.Win32.Downware.cwmdeh, Riskware.Win32.Downware.cypgup
21.43%

IKARUS anti.virus
PUA.Giraffe, Trojan.Win32.Spy, PUA.InstallBrain
21.43%

The domain www.appfael.com has been seen to resolve to the following 4 IP addresses.

50.97.49.242-static.reverse.softlayer.com
December 1, 2014

50.97.44.131-static.reverse.softlayer.com
December 1, 2014

174.37.181.31-static.reverse.softlayer.com
December 1, 2014

173.192.190.227-static.reverse.softlayer.com
December 1, 2014

File downloads found at URLs served by www.appfael.com.

The following 17 files have been seen to comunicate with www.appfael.com in live environments.

URL:
http://www.appfael.com/

Title:
“Contact Us”

Web server:
nginx/1.2.4 (PHP/5.3.16)