www.po114.org

xianlin xie

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the SoftLayer Technologies Inc. network.
Registrar:
GoDaddy.com, LLC

Server location:
Texas, United States (US)

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Root domain:

Scanner detections:
Detections  (89% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Elex.iSafe (M), PUP.337TechnologyLimited.H
100.00%

Kaspersky
not-a-virus:AdWare.Win32.D365
12.50%

Dr.Web
Adware.Mutabaha.29
12.50%

Vba32 AntiVirus
AdWare.D365
12.50%

Trend Micro House Call
TROJ_GEN.F47V1106
12.50%

Comodo Security
ApplicUnwnt
12.50%

ESET NOD32
Win32/ELEX (variant)
12.50%

IKARUS anti.virus
not-a-virus:AdWare.Win32.D365
12.50%

Fortinet FortiGate
Adware/D365
12.50%

Malwarebytes
PUP.Optional.Desk365.A
12.50%

NANO AntiVirus
Riskware.Win32.D365.csnrhl
12.50%

Avira AntiVirus
APPL/Downloader.Gen
12.50%

Boost by Reason
Optional.337TechnologyLimited.H
12.50%

Zillya! Antivirus
Adware.D365.Win32.4
12.50%

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
12.50%

The domain www.po114.org has been seen to resolve to the following 2 IP addresses.

173.193.180.132-static.reverse.softlayer.com
February 4, 2016

173.193.180.130-static.reverse.softlayer.com
February 4, 2016

File downloads found at URLs served by www.po114.org.

1 / 68      (PUP)
http://www.po114.org/.../iSafe_setup.exe  (ac5a2f3b1781c8e9254c52fff88c86ec)

1 / 68      (PUP)
http://www.po114.org/.../iSafe_setup.exe  (353435e1a468838202cb5c4ea7162904)

1 / 68      (PUP)

1 / 68      (PUP)
http://www.po114.org/.../iSafe_setup.exe  (5b8d8fd128bf187bda0487d000979092)

1 / 68      (PUP)
http://www.po114.org/.../iSafe_setup.exe  (7e72d0dc869aeead7c2b5db303988f20)

1 / 68      (PUP)
http://www.po114.org/.../iSafe_setup.exe  (205db9df3a1c01ed517251c65dfe9060)

1 / 68      (PUP)
http://www.po114.org/.../iSafe_setup.exe  (804404ff61bb3b15b371922f2a405cf0)

15 / 68    (Adware)

0 / 68

1 / 68      (PUP)
http://www.po114.org/.../iSafe_setup.exe  (718c5dfca9d8b073e56342e58b9987e2)

The following file have been seen to comunicate with www.po114.org in live environments.

URL:
http://www.po114.org/

Google Analytics:
UA-40570956

Title:
“Free Video Player, AVI/MKV/MP4/CD Player, Media Player Download”

Description:
“GoPlayer is a free & powerful video player which can help you enjoy various video files such as Flash, MKV, AVI, MP4 on PC.”

Web server:
nginx