dll513.fansfile.biz

Fundacion Private Whois  (Proxy Registrant)

Domain Information

The domain dll513.fansfile.biz is registered by proxy through INTERNET.BS CORP. and was originally registered in September of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Muenchen, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
INTERNET.BS CORP.

Server location:
Bayern, Germany (DE)

Create date:
Monday, September 15, 2014

Expires date:
Monday, September 14, 2015

Updated date:
Tuesday, October 7, 2014

ASN:
AS61969 TEAMINTERNET-AS Team Internet AG,DE

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP, PUP.Via Advertising.Bundler (M), PUP.Installer.RomirProduction.CC, PUP.Installer.RomirProduction.?, PUP.Installer.RomirProduction.z, PUP.Installer.RomirProduction.W, PUP.Installer.RomirProduction.T, PUP.Installer.RomirProduction.f, PUP.Via Advertising.RomirProduction.Bundler (M), PUP.Via Advertising.RomirPro.Bundler (M), PUP.Blisbury.NewMonte.Bundler (M), PUP.Via Advertising (M)
97.96%

VIPRE Antivirus
Threat.4783941, Threat.4412893
30.61%

ESET NOD32
Win32/ExpressDownloader (variant)
24.49%

Agnitum Outpost
PUA.Downware, Riskware.Agent
20.41%

AVG
Generic
18.37%

Dr.Web
Adware.Downware.8715, Adware.Downware.8924
16.33%

Avira AntiVirus
APPL/Downloader.Gen4, TR/Kazy.3785336
16.33%

IKARUS anti.virus
PUA.Expressdownloader
16.33%

Malwarebytes
PUP.Optional.Downloader
14.29%

AhnLab V3 Security
PUP/Win32.Downware
14.29%

F-Prot
W32/A-42de288b
14.29%

avast!
Win32:Adware-gen [Adw]
10.20%

K7 AntiVirus
Unwanted-Program
10.20%

MicroWorld eScan
Gen:Variant.Application.Bundler.24, Gen:Variant.Kazy.491253
8.16%

Bitdefender
Gen:Variant.Application.Bundler.24, Gen:Variant.Kazy.491253
8.16%

The domain dll513.fansfile.biz has been seen to resolve to the following 2 IP addresses.

June 21, 2016

October 20, 2014

File downloads found at URLs served by dll513.fansfile.biz.

 
Latest 30 of 49 download URLs

The following 26 files have been seen to comunicate with dll513.fansfile.biz in live environments.

 
Latest 20 of 26 files

URL:
http://dll513.fansfile.biz/

Web server:
nginx/0.7.67 (PHP/5.3.3-7+squeeze14)