b.datacardbar.info

S Jon Grant

Domain Information

Currently this domain has been known to host various forms of malware. The hosted servers are located in Beaumaris, Victoria within Australia which resides on the Asia Pacific Network Information Centre network.
Registrar:
Dynadot, LLC

Server location:
Victoria, Australia (AU)

ASN:
AS133618 TRELLIAN-AS-AP Trellian Pty. Limited,AU

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP, PUP.WebPick.StepanRy (M)
96.00%

Emsisoft Anti-Malware
Gen:Variant.Adware.Mikey.8516, Adware.Mplug.HN, Adware.MultiPlug.IL, Application.Bundler.Outbrowse.AW, Gen:Variant.Adware.MPlug.33
16.00%

McAfee
Program.MultiPlug-FWG, Multiplug-FXE, MultiPlug-FXE
14.00%

Dr.Web
Trojan.DownLoader12.42108, Trojan.DownLoader12.53687, Trojan.WebPick.6207, Trojan.DownLoader12.53311, Trojan.DownLoader12.42853
14.00%

Sophos
PUA 'MultiPlug' (of type Adware)
14.00%

K7 AntiVirus
Unwanted-Program
14.00%

AhnLab V3 Security
PUP/Win32.MultiPlug
14.00%

Vba32 AntiVirus
SScope.Adware.MultiPlug, suspected of Heur.Malware-Cryptor.Multiplug
14.00%

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
14.00%

Lavasoft Ad-Aware
Gen:Variant.Adware.Mikey.8516, Adware.Mplug.HN, Adware.MultiPlug.IL, Application.Bundler.Outbrowse.AW, Gen:Variant.Adware.MPlug.33
12.00%

AVG
Adware Generic_r.AAD, Generic6, Adware Generic6.ACSN, Adware Generic6.ACLE, Adware Generic6.ACRA
12.00%

MicroWorld eScan
Gen:Variant.Adware.Mikey.8516, Adware.Mplug.HN, Adware.MultiPlug.IL, Application.Bundler.Outbrowse.AW, Gen:Variant.Adware.MPlug.33
12.00%

F-Prot
W32/MultiPlug.H.gen, W32/S-eef9a8e7, W32/S-6a891bf2, W32/S-6e476ff7
12.00%

Bitdefender
Gen:Variant.Adware.Mikey.8516, Adware.Mplug.HN, Adware.MultiPlug.IL, Application.Bundler.Outbrowse.AW, Gen:Variant.Adware.MPlug.33
12.00%

NANO AntiVirus
Riskware.Win32.MultiPlug.doxmyn, Riskware.Win32.MultiPlug.dpyzpj, Riskware.Win32.MultiPlug.dqaekh, Riskware.Win32.MultiPlug.dpybfi
12.00%

The domain b.datacardbar.info has been seen to resolve to the following 6 IP addresses.

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
June 24, 2016

April 10, 2016

lb-182-246.above.com
July 1, 2015

ec2-54-200-195-191.us-west-2.compute.amazonaws.com
May 2, 2015

ec2-54-213-72-9.us-west-2.compute.amazonaws.com
May 2, 2015

ec2-54-68-13-248.us-west-2.compute.amazonaws.com
May 2, 2015

File downloads found at URLs served by b.datacardbar.info.

 
Latest 30 of 60 download URLs

The following 220 files have been seen to comunicate with b.datacardbar.info in live environments.

TCP » 54.72.9.51:80

 
Latest 20 of 224 files

URL:
http://b.datacardbar.info/

Google Analytics:
UA-19309218

Title:
“datacardbar.info - This website is for sale! - datacardbar Resources and Information.”

Description:
“This website is for sale! datacardbar.info is your first and best source for information about datacardbar . Here you will also find topics relating to issues of general interest. We hope you find what you are looking for!”

Web server:
Apache/2.2.22 (Debian)

30 of 93 related domains