dl.taketheseapps.com

Cloud4PC

Domain Information

The domain dl.taketheseapps.com registered by Cloud4PC was initially registered in May of 2016 through GANDI SAS. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Paris, Ile-De-France within France which resides on the Asia Pacific Network Information Centre network.
Registrar:
GANDI SAS

Server location:
Ile-De-France, France (FR)

Create date:
Tuesday, May 3, 2016

Expires date:
Wednesday, May 3, 2017

Updated date:
Tuesday, May 3, 2016

ASN:
AS12876 AS12876 ONLINE S.A.S., FR

Root domain:

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.Eorezo.Installer.Meta (M), Adware.Eorezo.uKl.Meta (M), Adware.Eorezo.iyfrlLby.Meta (M), Adware.Eorezo.ZZxnszF.Installer.Meta (M), Adware.Eorezo.qzhuKaNC.Installer.Meta (M), Adware.Eorezo.AtS.Meta (M), Adware.Eorezo.gJrbk.Meta (M), Adware.Eorezo.juteJ.Meta (M), Adware.Eorezo.eAldg.Installer.Meta (M), Adware.Eorezo.YRKsooHO.Installer.Meta (M), Adware.Eorezo.RHknCkz.Installer.Meta (M), Adware.Eorezo.Meta (M), Adware.Eorezo.ADGgaR.Meta (M), Adware.Eorezo.RNwsOrwb.Meta (M), Adware.Eorezo.aHSiEo.Meta (M), Adware.Eorezo.TOj.Meta (M), Adware.Eorezo.HWt.Meta (M), Adware.Eorezo.GAvV.Installer.Meta (M), Adware.Eorezo.MouxAafQ.Meta (M), Adware.Eorezo.pRiiJz.Installer.Meta (M), Adware.Eorezo.vxEal.Meta (M), Adware.Eorezo.FDr.Meta (M), Adware.Eorezo.zmv.Meta (M), Adware.Eorezo.ZQYY.Meta (M), Adware.Eorezo.VWKmhZl.Meta (M), Adware.Eorezo.ZLTjxq.Meta (M), Adware.Eorezo.aez.Installer.Meta (M), Adware.Eorezo.yYK.Meta (M), Adware.Eorezo.CnuhKK.Meta (M), Adware.Eorezo.rMDnls.Installer.Meta (M), Adware.Eorezo.syz4MxJv.Meta (M), Adware.Eorezo.ysm0Nt0h.Meta (M), Adware.Eorezo.merpS3.Meta (M), Adware.Eorezo.8g31QDX1.Meta (M), Adware.Eorezo.YOiY.Meta (M)
97.96%

ESET NOD32
MSIL/Injector.PMV trojan, Win32/AdWare.EoRezo.AU application
8.16%

Dr.Web
Adware.Eorezo.898
4.08%

McAfee
Trojan.Artemis!C9F5E9A28C02
2.04%

The domain dl.taketheseapps.com has been seen to resolve to the following 6 IP addresses.

dl3.wizzuniquify.com
June 4, 2016

dl4.wizzuniquify.com
June 4, 2016

dl5.wizzuniquify.com
June 4, 2016

dl1.wizzuniquify.com
June 4, 2016

dl2.wizzuniquify.com
June 4, 2016

dl0.wizzuniquify.com
June 4, 2016

File downloads found at URLs served by dl.taketheseapps.com.

2 / 68      (PUP)

URL:
http://dl.taketheseapps.com/

Title:
“Uniquify - Login”

Web server:
Apache/2.4.10 (Debian)