www.mp3searchbot.com

MP3 Rocket Inc

Domain Information

The domain www.mp3searchbot.com registered by MP3 Rocket Inc was initially registered in July of 2006 through Network Solutions, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Toronto, Ontario within Canada which resides on the Amanah Tech Inc. network.
Registrar:
Network Solutions, LLC

Server location:
Ontario, Canada (CA)

Create date:
Thursday, July 6, 2006

Expires date:
Tuesday, July 6, 2021

Updated date:
Wednesday, April 16, 2014

ASN:
AS32489 AMANAHA-NEW - Amanah Tech Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MP3Support.J, PUP.Installer.MP3Support.P, PUP.MP3Support.I, PUP.MP3Support.X, PUP.MP3Support.O, PUP.MP3Support.R, PUP.installCore.MP3TechSupport, Win32.Generic.SCCE.Installer.Meta, PUP.installCore.MP3TechS.Installer (M)
100.00%

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant), Win32/OpenCandy.A potentially unsafe (variant)
57.14%

Rising Antivirus
PE:Malware.XPACK/RDM!5.1, PE:Malware.Gamevance!6.5B4
21.43%

Trend Micro House Call
TROJ_GEN.F47V1119, TROJ_GEN.F47V0816
14.29%

Dr.Web
Adware.Downware.1417, Adware.OpenCandy.171
14.29%

Malwarebytes
PUP.Optional.Spigot.A
7.14%

Vba32 AntiVirus
Trojan.Agent.avfc
7.14%

VIPRE Antivirus
Trojan.Win32.Generic
7.14%

K7 AntiVirus
Unwanted-Program
7.14%

Zillya! Antivirus
Trojan.Kryptik.Win32.805012
7.14%

SUPERAntiSpyware
PUP.MP3Rocket/Variant
7.14%

Baidu Antivirus
Adware.Win32.OpenCandy
7.14%

AVG
Generic
7.14%

The domain www.mp3searchbot.com has been seen to resolve to the following 2 IP addresses.

December 1, 2014

184-75-214-134.amanah.com
February 5, 2014

File downloads found at URLs served by www.mp3searchbot.com.

1 / 68      (Adware)
http://www.mp3searchbot.com/.../mp3rocket.exe  (8d3c3b31dad0275328bd656871d333a6)

2 / 68      (PUP)

2 / 68      (PUP)
http://www.mp3searchbot.com/.../mp3rocket.exe  (dedcaeb5bf1a65fd8a64aa72e78cedcb)

2 / 68      (PUP)
http://www.mp3searchbot.com/.../mp3rocket.exe  (d0644c0b169c5054472cfd8242f8305d)

9 / 68      (PUP)
http://www.mp3searchbot.com/.../mp3rocket.exe  (4b524d4949d1a6752d59c78c4d204471)

2 / 68      (Adware)

1 / 68      (PUP)
http://www.mp3searchbot.com/.../mp3rocket.exe  (bc17886bea60db29b5b76977ba2eaf05)

3 / 68      (PUP)
http://www.mp3searchbot.com/.../mp3rocket.exe  (90fbf6594726a5a43f8a478f3b82699a)

2 / 68      (PUP)
http://www.mp3searchbot.com/.../mp3rocket.exe  (06cc5b20127a2e14a054b363ff7f310b)

2 / 68      (PUP)

1 / 68      (PUP)
http://www.mp3searchbot.com/.../mp3rocket.exe  (1600c7be96f563f8b3e1489da2866862)

2 / 68      (PUP)
http://www.mp3searchbot.com/.../mp3rocket.exe  (81532-669362-mp3-rocket.exe)

2 / 68      (PUP)

6 / 68      (PUP)
http://www.mp3searchbot.com/.../mp3rocket.exe  (cedd08917467257618f49507c7de7dbc)

The following file have been seen to comunicate with www.mp3searchbot.com in live environments.

URL:
http://www.mp3searchbot.com/

Web server:
Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4

Facebook:
Shares:  1

Statistics are for the previous month.