www.styleapplicationzillion.com

Whois Privacy Protection Service, Inc.  (Proxy Registrant)

Domain Information

The domain www.styleapplicationzillion.com is registered by proxy through NAME.COM, INC. and was originally registered in February of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Beaumaris, Victoria within Australia which resides on the Asia Pacific Network Information Centre network.
Registrar:
NAME.COM, INC.

Server location:
Victoria, Australia (AU)

Create date:
Tuesday, February 25, 2014

Expires date:
Wednesday, February 25, 2015

Updated date:
Tuesday, February 25, 2014

ASN:
AS133618 TRELLIAN-AS-AP Trellian Pty. Limited, AU

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP, PUP.AlexeyKurilenko.t, Adware.WebPick.Installer (M), Adware (M), PUP.WebPick (M)
100.00%

Malwarebytes
PUP.Optional.Installrex, PUP.Optional.DownloaderSS, PUP.Optional.InstalleRex
42.86%

avast!
Win32:InstalleRex-AI [PUP], Win32:InstalleRex-CH [PUP], Win32:InstalleRex-CK [PUP]
42.86%

Kaspersky
Trojan.Win32.AntiFW, not-a-virus:AdWare.Win32.MultiPlug
42.86%

Dr.Web
Adware.Downware.1541, Trojan.Crossrider.28215, Trojan.WebPick.2759
42.86%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696, Threat.4753027
42.86%

McAfee
PUP-FHQ!1F4116E31906, Trojan.Artemis!BB57FC5359EE, PUP-FHQ!D6BB6F2CE8EA
42.86%

NANO AntiVirus
Riskware.Win32.Downware.ctkpgl, Riskware.Win32.MultiPlug.ddsvpv, Riskware.Win32.InfoLeak.cvgqot
42.86%

Agnitum Outpost
PUA.InstalleRex, PUA.MultiPlug
28.57%

Comodo Security
Application.Win32.InstalleRex.KG, Application.Win32.GreenApp.RR
28.57%

Avira AntiVirus
Adware/InstallRex.X, Adware/MultiPlug.aob
28.57%

Sophos
InstallRex, MultiPlug
28.57%

ESET NOD32
Win32/InstalleRex.M potentially unwanted application
28.57%

AVG
MalSign.Generic, Adware Generic5
28.57%

Panda Antivirus
Adware/TSUploader, PUP/TSUploader
28.57%

The domain www.styleapplicationzillion.com has been seen to resolve to the following 6 IP addresses.

lb-182-207.above.com
July 9, 2016

ec2-52-26-71-172.us-west-2.compute.amazonaws.com
August 12, 2015

ec2-52-27-166-51.us-west-2.compute.amazonaws.com
August 12, 2015

ec2-52-27-146-26.us-west-2.compute.amazonaws.com
August 12, 2015

ec2-54-191-186-103.us-west-2.compute.amazonaws.com
August 17, 2014

ec2-54-187-76-32.us-west-2.compute.amazonaws.com
June 13, 2014

File downloads found at URLs served by www.styleapplicationzillion.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

29 / 68    (Adware)

The following 15 files have been seen to comunicate with www.styleapplicationzillion.com in live environments.

URL:
http://www.styleapplicationzillion.com/

Title:
“Welcome to nginx!”

Web server:
ngx_openresty (PHP/5.4.37)