zptechnology.com

Inmatrix LTD

Domain Information

The domain zptechnology.com registered by Inmatrix LTD was initially registered in May of 2007 through TUCOWS DOMAINS INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Anaheim, California within the United States which resides on the Lunar Pages network.
Registrar:
TUCOWS DOMAINS INC.

Server location:
California, United States (US)

Create date:
Tuesday, May 8, 2007

Expires date:
Sunday, May 8, 2016

Updated date:
Saturday, August 8, 2015

ASN:
AS15244 ADDD2NET-COM-INC-DBA-LUNARPAGES - Lunar Pages,US

Scanner detections:
Detections  (91% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Inmatrix.I, PUP.Inmatrix.J, PUP.Installer.Inmatrix, PUP.Inmatrix.Installer (M)
100.00%

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5, PE:Malware.Techsnab!6.2585 [F]
30.00%

McAfee
Artemis!E4561BA577B4, Artemis!5A5BC2074F19, Artemis!13972700CA4B
30.00%

Malwarebytes
PUP.Optional.OpenCandy
30.00%

G Data
Win32.Adware.OpenCandy, Win32.Application.OpenCandy
30.00%

ESET NOD32
Win32/OpenCandy.C potentially unsafe (variant), Win32/OpenCandy.A potentially unsafe (variant)
30.00%

K7 AntiVirus
Unwanted-Program
20.00%

Agnitum Outpost
Riskware.Agent
20.00%

Fortinet FortiGate
Riskware/OpenCandy
20.00%

Dr.Web
Adware.OpenCandy.176
10.00%

Avira AntiVirus
PUA/OpenCandy.Gen
10.00%

The domain zptechnology.com has been seen to resolve to the following IP address.

shu.lunarservers.com
September 2, 2014

File downloads found at URLs served by zptechnology.com.

0 / 68
http://zptechnology.com/.../zp1210free.exe  (bf1f310892c074191c43483e6983bd18)

8 / 68      (PUP)
http://zptechnology.com/.../zp1100free.exe  (ca6923aa839ee27cf42af2e585d540a9)

1 / 68      (PUP)
http://zptechnology.com/.../zp1200free.exe  (90f3d39cec05934182222fe213c65d13)

1 / 68      (PUP)
http://zptechnology.com/.../zp1200max.exe  (581f19cc0f69b585e3bc5791db520f5b)

6 / 68      (PUP)
http://zptechnology.com/.../zp1000free.exe  (295d2cbe645f634658be4f685467002a)

1 / 68      (PUP)
http://zptechnology.com/.../zp1110pro.exe  (f8f5af8d95e1275a9e7c6a361f0b55b5)

2 / 68      (PUP)
http://zptechnology.com/.../zp861free.exe  (6eebdbd03804dd38ec76bf85660a91d2)

10 / 68    (PUP)
http://zptechnology.com/.../zp1110free.exe  (13972700ca4bd03ec375f86331155761)

2 / 68      (PUP)
http://zptechnology.com/.../zp1110max.exe  (7e102a877f062b9e53b2df88f0f222b3)

1 / 68      (PUP)
http://zptechnology.com/.../zp861pro.exe  (f1892def338afabbf8ade612910ed505)

1 / 68      (PUP)
http://zptechnology.com/.../zp861max.exe  (3ec3a7bdf9234f36974084f9823e0c98)

The following 2 files have been seen to comunicate with zptechnology.com in live environments.

September 2, 2014

URL:
http://zptechnology.com/

Web server:
Apache/2.0.64 (Unix) mod_ssl/2.0.64 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 mod_fcgid/2.3.6