cpdownload.simplyinstaller.com

One Floor App LTD

Domain Information

The domain cpdownload.simplyinstaller.com registered by Yossi Marouani was initially registered in October of 2012 through WILD WEST DOMAINS, LLC. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Petah Tikva, Hamerkaz within Israel which resides on the RIPE Network Coordination Centre network. The domain is associated with the publisher One Floor App LTD who is located in Bnei Brak, Israel.
Registrar:
WILD WEST DOMAINS, LLC

Server location:
Hamerkaz, Israel (IL)

Create date:
Thursday, October 18, 2012

Expires date:
Tuesday, October 18, 2016

Updated date:
Monday, October 19, 2015

ASN:
AS8551 BEZEQ-INTERNATIONAL-AS Bezeqint Internet Backbone

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.OneFloorApp.H, PUP.Installer.OneFloorApp.Q, PUP.Widdit.OneFloorApp.Bundler (M), PUP.Widdit.OneFloor.Bundler (M), PUP.Widdit (M)
100.00%

Avira AntiVirus
ADWARE/Adware.Gen
20.41%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
18.37%

Dr.Web
Adware.Downware.3113, Adware.Redsky.3, Adware.Downware.3113
18.37%

Malwarebytes
PUP.Optional.SimplyInstaller.A, PUP.Optional.OneFloorApp
18.37%

ESET NOD32
Win32/Toolbar.Widdit.A potentially unwanted application
18.37%

IKARUS anti.virus
PUA.Toolbar.Widdit, AdWare.Toolbar
18.37%

AVG
Onefloorap
18.37%

Qihoo 360 Security
Malware.QVM06.Gen
18.37%

Sophos
SimplyInstaller, Generic PUA FL, PUA 'SimplyInstaller'
18.37%

McAfee
PUP-FNE
18.37%

Trend Micro House Call
Suspicious_GEN.F47V0805
18.37%

Baidu Antivirus
PUA.Win32.Widdit
18.37%

Fortinet FortiGate
Riskware/Widdit
18.37%

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
18.37%

The domain cpdownload.simplyinstaller.com has been seen to resolve to the following 2 IP addresses.

January 8, 2015

bzq-179-38-67.static.bezeqint.net
June 21, 2014

File downloads found at URLs served by cpdownload.simplyinstaller.com.

 
Latest 30 of 49 download URLs

The following 4 files have been seen to comunicate with cpdownload.simplyinstaller.com in live environments.

URL:
http://cpdownload.simplyinstaller.com/

Title:
“One Floor App - Boutique Apps”

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)