www.fpstool.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain www.fpstool.com is registered by proxy through ENOM, INC. and was originally registered in July of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
Arizona, United States (US)

Create date:
Tuesday, July 16, 2013

Expires date:
Sunday, July 16, 2017

Updated date:
Saturday, July 9, 2016

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc., US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

ESET NOD32
MSIL/HackTool.Facebook.A potentially unsafe application
100.00%

McAfee
RDN/Generic PUP.z
100.00%

VIPRE Antivirus
Trojan.Win32.Generic
100.00%

K7 AntiVirus
Unwanted-Program
100.00%

NANO AntiVirus
Trojan.Win32.Facebook.dvkthd
100.00%

Trend Micro House Call
TROJ_GE.1C1F58BB
100.00%

Sophos
Generic PUA MP (PUA)
100.00%

G Data
Win32.Application.Agent.0X281Z
100.00%

Baidu Antivirus
Hacktool.MSIL.Facebook
100.00%

Qihoo 360 Security
vbs.vbswormgen.2.a
100.00%

The domain www.fpstool.com has been seen to resolve to the following 2 IP addresses.

July 17, 2016

July 17, 2016

File downloads found at URLs served by www.fpstool.com.

10 / 68    (PUP)

URL:
http://www.fpstool.com/

Title:
“Facebook Password Sniper”

Description:
“The official website of Facebook Password Sniper, the best and the safest hack tool out there.”

Web server:
cloudflare-nginx (PHP/5.5.30)

Facebook:
Likes:  318
Shares:  800
Comments:  407

Statistics are for the previous month.