www.webnewapp.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.webnewapp.com is registered by proxy through GODADDY.COM, LLC and was originally registered in May of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Thursday, May 3, 2012

Expires date:
Tuesday, May 3, 2016

Updated date:
Monday, May 4, 2015

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Sophos
Install Core, vGrabber
100.00%

Dr.Web
Adware.InstallCore.43, Adware.Downware.336, Adware.Zugo.106
100.00%

G Data
Trojan.Generic.7624916, NSIS:Bundlore-C , NSIS:Adware-DR
100.00%

Vba32 AntiVirus
BScope.Trojan.MTA.0157, suspected of Trojan.Downloader.gen.h
100.00%

ESET NOD32
Win32/InstallCore (variant), Win32/Adware.Bundlore
100.00%

Trend Micro House Call
ADW_INSTALLCORE, TROJ_SPNR.03IP12
66.67%

Clam AntiVirus
W32.Adware.InstallCore-1, Adware.Downware-1
66.67%

VIPRE Antivirus
Click run software, Trojan.Win32.Generic
66.67%

Avira AntiVirus
ADWARE/InstallCore.Gen, Adware/Zugo.C.1
66.67%

Trend Micro
ADW_INSTALLCORE, TROJ_SPNR.03IP12
66.67%

Emsisoft Anti-Malware
Win32.SuspectCrc!IK, Adware.Win32.Bundlore.AMN
66.67%

Fortinet FortiGate
W32/InstallCore.T, Riskware/Bundlore
66.67%

McAfee
Generic PUP.x!bhc, Artemis!63548AB91A65
66.67%

avast!
NSIS:Bundlore-C [Adw], NSIS:Adware-DR [Adw]
66.67%

nProtect
Trojan.Generic.7624916
33.33%

The domain www.webnewapp.com has been seen to resolve to the following IP address.

ip-184-168-221-67.ip.secureserver.net
May 25, 2016

File downloads found at URLs served by www.webnewapp.com.

17 / 68    (PUP)

8 / 68      (PUP)

22 / 68    (Adware)

22 / 68    (Adware)
http://www.webnewapp.com/download/.../Downloader.exe  (e3e0eb102463ae1ebc270b025dcc14c3)