www.ziputil.net

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain www.ziputil.net is registered by proxy through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM and was originally registered in February of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Wednesday, February 22, 2012

Expires date:
Wednesday, February 22, 2017

Updated date:
Friday, January 29, 2016

Root domain:

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.installCore.FriedCoo.Installer (M), PUP.installCore.JumpyApp.Installer (M), PUP.installCore.ComboApp.Installer (M), PUP.installCore (M), PUP.InstallCore (M)
97.92%

Bkav FE
W32.Clod853.Trojan
2.08%

McAfee
Artemis!500EFB844629
2.08%

K7 AntiVirus
Unwanted-Program
2.08%

K7 Gateway Antivirus
Unwanted-Program
2.08%

Trend Micro House Call
TROJ_GEN.F47V1120
2.08%

Dr.Web
Adware.InstallCore.133
2.08%

VIPRE Antivirus
InstallCore
2.08%

McAfee Web Gateway
Artemis!500EFB844629
2.08%

Sophos
Install Core Click run software
2.08%

ESET NOD32
Win32/InstallCore.GB
2.08%

ESET NOD32
Win32/Kryptik.BWAM trojan
2.08%

The domain www.ziputil.net has been seen to resolve to the following 52 IP addresses.

May 23, 2016

.
May 22, 2016

May 22, 2016

May 17, 2016

April 21, 2016

April 20, 2016

April 17, 2016

April 14, 2016

April 10, 2016

April 8, 2016

April 8, 2016

April 8, 2016

April 7, 2016

April 7, 2016

April 4, 2016

.
April 4, 2016

April 3, 2016

April 2, 2016

.
April 2, 2016

April 1, 2016

March 31, 2016

November 7, 2015

ip-50-63-202-104.ip.secureserver.net
May 5, 2015

unallocated.barefruit.co.uk
August 1, 2014

ec2-54-197-239-246.compute-1.amazonaws.com
June 21, 2014

ec2-184-73-205-143.compute-1.amazonaws.com
June 21, 2014

ec2-50-19-247-199.compute-1.amazonaws.com
June 21, 2014

ec2-23-23-228-190.compute-1.amazonaws.com
June 21, 2014

ec2-54-243-86-8.compute-1.amazonaws.com
April 20, 2014

ec2-23-21-204-175.compute-1.amazonaws.com
April 20, 2014

 
Showing 30 of 52 IP Addresses

File downloads found at URLs served by www.ziputil.net.

1 / 68      (Adware)

The following 234 files have been seen to comunicate with www.ziputil.net in live environments.

 
Latest 20 of 234 files

URL:
http://www.ziputil.net/

Title:
“Loading....”

Title (1/4/2014):
“Zip Opener”

Title (5/5/2015):
“ziputil.net”

Web server:
Apache-Coyote/1.1