de.windows8codecs.com

Cole Williams

Domain Information

The domain de.windows8codecs.com registered by Cole Williams was initially registered in August of 2009 through OVH. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Anaheim, California within the United States.
Registrar:
OVH

Server location:
California, United States (US)

Create date:
Sunday, August 9, 2009

Expires date:
Tuesday, August 9, 2016

Updated date:
Sunday, August 9, 2015

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Detections  (67% detected)

Scan engine
Details
Detections

Trend Micro House Call
Suspicious_GEN.F47V0307, Suspicious_GEN.F47V0612
66.67%

ESET NOD32
Win32/Toolbar.Widgi.N potentially unwanted (variant), Win32/OpenCandy.C potentially unsafe (variant)
66.67%

Reason Heuristics
PUP.Installer.ColeWilliams.AA
33.33%

McAfee
Artemis!2A69647E32A1
33.33%

K7 AntiVirus
Unwanted-Program
33.33%

avast!
Win32:Adware-gen [Adw]
33.33%

Dr.Web
Adware.OpenCandy.137
33.33%

VIPRE Antivirus
Opencandy
33.33%

G Data
NSIS.Application.OpenCandy
33.33%

Fortinet FortiGate
Riskware/OpenCandy
33.33%

AVG
OpenCandy
33.33%

The domain de.windows8codecs.com has been seen to resolve to the following 4 IP addresses.

ip31.ip-149-56-65.net
April 6, 2016

ip32.ip-149-56-65.net
April 6, 2016

May 5, 2015

May 5, 2015

File downloads found at URLs served by de.windows8codecs.com.

10 / 68    (PUP)

1 / 68      (PUP)

2 / 68      (inconclusive)

URL:
http://de.windows8codecs.com/

Title:
“Windows 8 Codecs Pack for Windows Media Player WMP12 and Media Center”

Web server:
Apache (PHP/7.0.4)