www.xflv-player.net

Whois Privacy Corp.

Domain Information

The domain www.xflv-player.net registered by Whois Privacy Corp. was initially registered in October of 2014 through TLD REGISTRAR SOLUTIONS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network.
Registrar:
TLD REGISTRAR SOLUTIONS LTD

Server location:
Dublin City, Ireland (IE)

Create date:
Friday, October 31, 2014

Expires date:
Monday, October 31, 2016

Updated date:
Sunday, November 1, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SarinratSubindee.Q, PUP.RungnapaFongkerd.Q, PUP.VASSANAKONGSOONGNERN.Q, PUP.VASSANAKONGSOONGNERN.I, PUP.CoolMirage
100.00%

AVG
Generic, Rungnapa
87.50%

Dr.Web
Adware.Downware.6586, Adware.Downware.8319, Adware.Yontoo.54
75.00%

Sophos
FT Downloader, CoolMirage, Generic PUA NP, Generic PUA OG
62.50%

K7 AntiVirus
Adware
62.50%

Kaspersky
not-a-virus:AdWare.NSIS.Yontoo, not-a-virus:Downloader.Win32.TornTV
62.50%

ESET NOD32
NSIS/TrojanDownloader.Adload.AA, NSIS/TrojanDropper.Agent.CB
62.50%

VIPRE Antivirus
CoolMirage Ltd
50.00%

McAfee
Artemis!D78BDE0FE37C, Artemis!CF0F519D3F0A, Artemis!77BB31D9AA84
37.50%

Trend Micro House Call
Suspicious_GEN.F47V1124, Suspicious_GEN.F47V1227, Suspicious_GEN.F47V0216
37.50%

Baidu Antivirus
Adware.NSIS.Yontoo, Trojan.MSIL.ShimChanger
37.50%

G Data
NSIS.Application.Adload
25.00%

Panda Antivirus
Generic Suspicious
12.50%

Avira AntiVirus
TR/Dldr.Adload.76248
12.50%

Malwarebytes
Trojan.MSIL.Injector
12.50%

The domain www.xflv-player.net has been seen to resolve to the following 3 IP addresses.

ns1.ibspark.com
November 19, 2015

ec2-54-241-246-64.us-west-1.compute.amazonaws.com
November 3, 2014

ec2-54-241-29-126.us-west-1.compute.amazonaws.com
November 3, 2014

File downloads found at URLs served by www.xflv-player.net.

 
Latest 30 of 153 download URLs

The following 142 files have been seen to comunicate with www.xflv-player.net in live environments.

 
Latest 20 of 154 files

URL:
http://www.xflv-player.net/

Title:
“xflv-player.net”

Web server:
nginx