www.mynicepicks.com

Corp New Ventures Services

Domain Information

The domain www.mynicepicks.com registered by Corp New Ventures Services was initially registered in October of 2015 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
DOMAINSAREFOREVER.NET LLC

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Monday, October 5, 2015

Expires date:
Wednesday, October 5, 2016

Updated date:
Monday, October 12, 2015

Root domain:

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

avast!
NSIS:Adware-EH [PUP], NSIS:Ezula-BC [Adw], NSIS:Bundlore-B [Adw], Rootkit-gen [Rtk], NSIS:Adware-DM [Trj], NSIS:Adware-DR [Adw]
79.17%

VIPRE Antivirus
Bundlore, Trojan.Win32.Generic, InstallCore, Threat.4721115
75.00%

McAfee
GenericTRA-BJ!6E6FA0C56CD7, Artemis!90C726412EC2, Artemis!BF563BC793A9, RDN/Generic PUP.x!bch, RDN/Generic PUP.x!bnf, Artemis!79CD0BA3574F, Artemis!0BCD1FF0D3C0, RDN/Generic PUP.x!et, Artemis!D0696304D142, RDN/Generic PUP.x!bfb, GenericTRA-AR!7A1F2FE39DC2, RDN/Generic PUP.x!bnr, Generic Malware.nl!ats
75.00%

Avira AntiVirus
Adware/Bundlore.C, Adware/Zugo.C.2, Adware/Zugo.C.1, APPL/Downloader.Gen, ADWARE/Adware.Gen, ADWARE/InstallCore.Gen
75.00%

Dr.Web
Adware.Downware.514, Adware.Downware.438, Adware.Downware.830, Adware.SweetIM.3, Adware.Zugo.64, Adware.Toolbar.240, Trojan.DownLoader7.7108
70.83%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, Adware.InstallCore.gen
70.83%

Malwarebytes
PUP.BundleInstaller.VG, PUP.Optional.Bundlore.A, Trojan.FakeVLC, PUP.Optional.AdBundle, PUP.Optional.BundleInstaller.VG
66.67%

ESET NOD32
Win32/Adware.Bundlore, Win32/TrojanDownloader.Adload.NMV, Win32/InstallCore (variant)
66.67%

Trend Micro House Call
TROJ_GEN.R0CBC0OI513, TROJ_GEN.F47V0406, TROJ_HEUR_0000028.TOMA, TROJ_GEN.R0CBH0AK113, TROJ_SPNR.14B713, TROJ_GE.0B3F6F3F
66.67%

NANO AntiVirus
Riskware.Nsis.Downware.yrefc, Trojan.Win32.VOPackage.dejkod, Riskware.Win32.WebToolbarInst.utxfq, Riskware.Win32.Toolbar.dgkvzs
66.67%

Fortinet FortiGate
Riskware/Bundlore, W32/Adload.NMV!tr.dldr, Adware/Zugo
62.50%

Sophos
vGrabber, VOPackage, vGrabber (PUA)
58.33%

Baidu Antivirus
Adware.Win32.Bundlore, Adware.Win32.Ask, Adware.Win32.InstallCore, AdWare.Win32.Bundlore, Hacktool.Win32.Toolbar
54.17%

Reason Heuristics
PUP.Bundlore.Q, PUP.Installer.Bundlore.F, PUP.Bundlore.T, PUP.Optional.Installer.F, PUP.InstallCore.Q, PUP.VGrabber.Installer.Bundler.Installer.Meta (L), PUP.Vittalia.InstallA.Installer (M)
45.83%

AVG
MultiBundle.H, AdInstaller.Bundlor, Adware Vopackage.D, Win32/Sality
33.33%

The domain www.mynicepicks.com has been seen to resolve to the following 3 IP addresses.

May 16, 2016

November 13, 2015

unallocated.barefruit.co.uk
May 5, 2015

File downloads found at URLs served by www.mynicepicks.com.

7 / 68      (Malware)

13 / 68    (PUP)

17 / 68    (PUP)

14 / 68    (PUP)

1 / 68      (Adware)
http://www.mynicepicks.com/download/.../setup.exe  (cfe253a4aae21867e778413b7a635509)

1 / 68      (PUP)
http://www.mynicepicks.com/download/.../setup.exe  (55c372ee60302c4f867f59d47c8e3dd9)

18 / 68    (PUP)
http://www.mynicepicks.com/download/.../setup.exe  (6b319b236d7ff60a21e328d108cde41a)

12 / 68    (PUP)
http://www.mynicepicks.com/download/.../Downloader.exe  (d2c7e2499c341346a3b2e8404fe86be1)

12 / 68    (PUP)

1 / 68      (PUP)
http://www.mynicepicks.com/download/.../setup.exe  (306797979faa4df693e965d5b32e1987)

17 / 68    (PUP)
http://www.mynicepicks.com/download/.../setup.exe  (8e8c81523bf187fc9ca87755b242bddd)

7 / 68      (PUP)
http://www.mynicepicks.com/download/.../setup.exe  (fbee4c0ff3e6f91c6a3901a53d852a74)

10 / 68    (PUP)

19 / 68    (Adware)

24 / 68    (Adware)

0 / 68
http://www.mynicepicks.com/download/.../setup.exe  (cc422bd894aeb4a84fd4d8b848fbb873)

21 / 68    (Adware)

17 / 68    (PUP)
http://www.mynicepicks.com/download/.../Downloader.exe  (26a9872f2d3a2373d51deaeedbf5717e)

17 / 68    (Adware)

19 / 68    (PUP)
http://www.mynicepicks.com/download/.../setup.exe  (90c726412ec20807eae6c1a3d72aecdd)

24 / 68    (Adware)

22 / 68    (PUP)

The following 233 files have been seen to comunicate with www.mynicepicks.com in live environments.

 
Latest 20 of 233 files

URL:
http://www.mynicepicks.com/

Web server:
Apache