www.skrifttyperfonter.com

David Fimia

Domain Information

The domain www.skrifttyperfonter.com registered by David Fimia was initially registered in December of 2008 through Moniker Online Services. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Nuremberg, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
Moniker Online Services

Server location:
Bayern, Germany (DE)

Create date:
Saturday, December 27, 2008

Expires date:
Tuesday, December 27, 2016

Updated date:
Tuesday, December 22, 2015

ASN:
AS24940 HETZNER-AS Hetzner Online GmbH,DE

Scanner detections:
Detections  (90% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer.U, Adware.WebPick.Installer.R, Adware.WebPick.Installer.O, PUP.OlehAleksyuk (M), Threat.Win.Reputation.IMP, Adware.WebPick.Installer (M), PUP.OlehAlek (M), PUP.WebPick.Stanisla (M), Adware.FreshApp.Installer (M), Adware.GreenApp.Installer (M), Adware (M), PUP (M), PUP.WebPick (M)
88.89%

ESET NOD32
Win32/InstalleRex.P potentially unwanted application, Win32/InstalleRex.M potentially unwanted application, Win32/AdWare.MultiPlug.CN application, Win32/AdWare.MultiPlug.CT application
20.00%

McAfee
PUP-FHQ!689455D83A4C, PUP-FHQ!C337F507E467, MultiPlug-FRE, Program.PUP-FHQ, Program.MultiPlug-FVH, Program.MultiPlug-FRO
20.00%

AVG
Generic, Generic5, Adware Generic6.LZI, Adware Generic_r.VD, Adware Generic_r.UH
20.00%

Emsisoft Anti-Malware
Gen:Variant.Strictor.55208, Gen:Variant.Adware.MPlug.10, Gen:Variant.Strictor.58380, Application.Generic.684775, Gen:Variant.Adware.Multiplug.11
17.78%

Dr.Web
Trojan.WebPick.29, Trojan.WebPick.2452, Trojan.WebPick.2735, Trojan.Crossrider.37956, Trojan.Crossrider.36808, Trojan.Crossrider.36840
15.56%

avast!
Win32:InstalleRex-BI [PUP], Win32:InstalleRex-BO [PUP], Win32:InstalleRex-CD [PUP], Win32:InstalleRex-CG [PUP], Win32:Agent-AYLT [PUP]
15.56%

Kaspersky
Trojan.Win32.AntiFW, not-a-virus:HEUR:AdWare.Win32.MultiPlug, not-a-virus:AdWare.Win32.MultiPlug
15.56%

Sophos
InstallRex, MultiPlug, PUA 'InstallRex', PUA 'MultiPlug' (of type Adware)
15.56%

K7 Gateway Antivirus
Unwanted-Program
13.33%

K7 AntiVirus
Unwanted-Program
13.33%

NANO AntiVirus
Riskware.Win32.InfoLeak.cvgqot, Riskware.Win32.MultiPlug.dfjscb, Trojan.Win32.Crossrider1.dnprgd
13.33%

Comodo Security
Application.Win32.InstalleRex.KG, Application.Win32.MultiPlug.PNU, Application.Win32.AdWare.MultiPlug.VA
13.33%

Avira AntiVirus
TR/Kazy.324119.5, Adware/InstallRex.ode.17, Adware/MPlug.yvg, Adware/InstalleRex.M.1, ADWARE/MultiPlug.Gen7
13.33%

McAfee Web Gateway
PUP-FHQ!689455D83A4C, PUP-FHQ!C337F507E467, BehavesLike.Win32.Trojan.bc, BehavesLike.Win32.Downloader.fc, BehavesLike.Win32.Trojan.tc
13.33%

The domain www.skrifttyperfonter.com has been seen to resolve to the following 2 IP addresses.

servidor2.gifmania.com
January 27, 2016

servidor.gifmania.com
May 18, 2014

File downloads found at URLs served by www.skrifttyperfonter.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Malware)

9 / 68      (PUP)

1 / 68      (Adware)

1 / 68      (Malware)

1 / 68      (Adware)

 
Latest 30 of 51 download URLs

The following 3 files have been seen to comunicate with www.skrifttyperfonter.com in live environments.

URL:
http://www.skrifttyperfonter.com/

Google Analytics:
UA-20985651

Title:
“Fonter til nedlasting”

Description:
“Fonter til nedlasting!! Tusenvis av gratis Skrifter til nedlasting. Bokstaven og skrifter for Word og Windows. Typografiske TTF true type”

Web server:
Apache/2.2.29 (Unix) mod_ssl/2.2.29 OpenSSL/1.0.1e-fips PHP/5.4.45

Facebook:
Likes:  16
Shares:  14
Comments:  2

Statistics are for the previous month.