5kplayer.gammatechsoft.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain 5kplayer.gammatechsoft.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2016. Currently this domain has been known to host various forms of malware. The hosted servers are located in Carrollton, Texas within the United States which resides on the WEBSITEWELCOME.COM network.
Registrar:
GODADDY.COM, LLC

Server location:
Texas, United States (US)

Create date:
Wednesday, March 2, 2016

Expires date:
Thursday, March 2, 2017

Updated date:
Wednesday, March 2, 2016

ASN:
AS20013 CYRUSONE - CyrusOne LLC, US

Root domain:

Scanner detections:
Malware distribution  (67% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/Sality.NBA virus
66.67%

avast!
Win32:SaliCode
66.67%

F-Prot
W32/Sality.gen2
66.67%

Kaspersky
Virus.Win32.Sality
66.67%

Dr.Web
Win32.Sector.22, Win32.Sector.30
66.67%

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
33.33%

Emsisoft Anti-Malware
Win32.Sality
33.33%

VIPRE Antivirus
Threat.4721115
33.33%

McAfee
Virus.W32/Sality.gen.z
33.33%

Sophos
Virus 'Mal/Sality-D'
33.33%

Norman
Win32.Sality.3
33.33%

The domain 5kplayer.gammatechsoft.com has been seen to resolve to the following 2 IP addresses.

April 21, 2016

April 12, 2016

File downloads found at URLs served by 5kplayer.gammatechsoft.com.

9 / 68      (Infected)
http://5kplayer.gammatechsoft.com/5kplayer.exe  (0064f3fae7457f2b2a821a1ec6294f47)

6 / 68      (Malware)
http://5kplayer.gammatechsoft.com/5kplayer.exe  (250ad32e6ed9794ddfde7330f2c561d1)

1 / 68
http://5kplayer.gammatechsoft.com/5kplayer.exe  (a56d05f88143bdf38f78c49ccbc01f0a)

URL:
http://5kplayer.gammatechsoft.com/

Web server:
nginx/1.8.1