www.mannesoth.com

Whois Privacy Corp.

Domain Information

The domain www.mannesoth.com registered by Whois Privacy Corp. was initially registered in March of 2014 through INTERNET.BS CORP.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Remove Malware from www.mannesoth.com - Powered by Reason Core Security
Registrar:
INTERNET DOMAIN SERVICE BS CORP

Server location:
Dublin City, Ireland (IE)

Create date:
Tuesday, March 18, 2014

Expires date:
Friday, March 18, 2016

Updated date:
Wednesday, December 16, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Root domain:

Google Safe Browsing:
malware

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SOFTWAREAGILITYLIMITED.CC, PUP.SOFTWAREAGILITYLIMITED.BB, PUP.SOFTWAREAGILITYLIMITED.Y, PUP.SOFTWAREAGILITYLIMITED.?, PUP.SOFTWAREAGILITYLIMITED.s, PUP.SOFTWAREAGILITYLIMITED.Q, PUP.SOFTWAREAGILITYLIMITED.c, PUP.SOFTWAREAGILITYLIMITED.f, PUP.SOFTWAREAGILITYLIMITED.EE, PUP.SOFTWAREAGILITYLIMITED.DD, PUP.SOFTWAREAGILITYLIMITED.q, PUP.SOFTWAREAGILITYLIMITED.X, PUP.Installer.SOFTWAREAGILITYLIMITED.F, PUP.SOFTWAREAGILITY.Bundler.Meta (M), PUP.SOFTWAREAGILITYLIMITED.a, PUP.SOFTWAREAGILITYLIMITED.t, PUP.SOFTWAREAGILITYLIMITED.h, PUP.SOFTWAREAGILITYLIMITED.S, PUP.SOFTWAREAGILITYLIMITED.AA, PUP.SOFTWAREAGILITY (M)
100.00%

avast!
Win32:Malware-gen, Win32:Rootkit-gen [Rtk], Win32:Adware-gen [Adw]
90.63%

AVG
Bundle, Adware Generic5.AYIZ, Adware Generic5.AYIW, Adware Generic5.BCOT
90.63%

ESET NOD32
Win32/BundleInstaller.F potentially unwanted application, Win32/BundleInstaller.G potentially unwanted application, Win32/Amonetize.AV potentially unwanted application
84.38%

Malwarebytes
PUP.Optional.FilePile, PUP.Optional.FineDream
75.00%

MicroWorld eScan
Gen:Variant.Graftor.141359, Gen:Variant.Adware.Graftor.143702, Gen:Variant.Kazy.413212, Gen:Variant.Adware.Kazy.413212, Gen:Variant.Adware.Graftor.148401
71.88%

Bitdefender
Gen:Variant.Graftor.141359, Gen:Variant.Adware.Graftor.143702, Gen:Variant.Kazy.413212, Gen:Variant.Adware.Kazy.413212, Gen:Variant.Adware.Graftor.148401
71.88%

Emsisoft Anti-Malware
Gen:Variant.Graftor.141359, Gen:Variant.Adware.Graftor.143702, Gen:Variant.Kazy.413212, Gen:Variant.Adware.Kazy.413212, Gen:Variant.Adware.Graftor.148401
71.88%

G Data
Gen:Variant.Graftor.141359, Gen:Variant.Adware.Graftor.143702, Gen:Variant.Kazy.413212, Gen:Variant.Adware.Kazy.413212, Gen:Variant.Adware.Graftor.148401
71.88%

Kaspersky
not-a-virus:Downloader.Win32.Agent
71.88%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
68.75%

Lavasoft Ad-Aware
Gen:Variant.Graftor.141359, Gen:Variant.Adware.Graftor.143702, Gen:Variant.Kazy.413212, Gen:Variant.Adware.Kazy.413212, Gen:Variant.Adware.Graftor.148401
68.75%

F-Secure
Gen:Variant.Graftor.141359, Gen:Variant.Adware.Graftor.143702, Gen:Variant.Kazy.413212, Gen:Variant.Adware.Kazy.413212, Gen:Variant.Adware.Graftor.148401
68.75%

Panda Antivirus
Suspicious file, Trj/Genetic.gen
68.75%

IKARUS anti.virus
PUA.Bundler, PUA.BundleInstaller, PUA.OxyPumper, AdWare.OxyPumper
65.63%

The domain www.mannesoth.com has been seen to resolve to the following 3 IP addresses.

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
January 4, 2016

June 13, 2014

May 28, 2014

File downloads found at URLs served by www.mannesoth.com.

1 / 68      (Adware)

22 / 68    (Adware)

1 / 68      (Adware)

21 / 68    (Adware)

17 / 68    (Adware)

19 / 68    (Adware)

19 / 68    (Adware)

20 / 68    (Adware)

23 / 68    (Adware)

18 / 68    (Adware)

7 / 68      (Adware)

6 / 68      (Adware)

23 / 68    (Adware)

6 / 68      (Adware)

6 / 68      (Adware)

24 / 68    (Adware)

23 / 68    (Adware)
http://www.mannesoth.com/.../nigerian_standard_code_of_practice_nscp_i_1973_part_3_loading.rar_Downloader_14000004.exe  (nigerian_standard_code_of_practice_nscp_i_1973_part_3_loading.rar_downloader.exe)

18 / 68    (Adware)

18 / 68    (Adware)

15 / 68    (Adware)

 
Latest 30 of 32 download URLs

The following 7 files have been seen to comunicate with www.mannesoth.com in live environments.

URL:
http://www.mannesoth.com/

Title:
“mannesoth.com”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx

Facebook:
Likes:  2
Shares:  3

Statistics are for the previous month.

Remove Malware from www.mannesoth.com - Powered by Reason Core Security