dll513.webfilebase.biz

Whois Privacy Corp.

Domain Information

The domain dll513.webfilebase.biz registered by Whois Privacy Corp. was initially registered in September of 2014 through INTERNET.BS CORP.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Chicago, Illinois within the United States which resides on the FDCservers.net network.
Registrar:
INTERNET.BS CORP.

Server location:
Illinois, United States (US)

Create date:
Monday, September 15, 2014

Expires date:
Monday, September 14, 2015

Updated date:
Monday, September 15, 2014

ASN:
AS6461 ABOVENET - Abovenet Communications, Inc,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ViaAdvertisingGroupLimited.n, PUP.Installer.ViaAdvertisingGroupLimited.EE, PUP.Installer.ViaAdvertisingGroupLimited.HH, PUP.Installer.ViaAdvertisingGroupLimited.e, PUP.Installer.ViaAdvertisingGroupLimited.t, PUP.Via Advertising.ViaAdvertisingGroup.Bundler (M), PUP.Via Advertising.ViaAdver.Bundler (M), PUP.Via Advertising (M)
100.00%

VIPRE Antivirus
Threat.4758264
20.00%

avast!
Win32:Downloader-UEO [PUP]
20.00%

Dr.Web
Adware.Downware.8424, Adware.Downware.8715, Adware.Downware.8624
20.00%

Malwarebytes
PUP.Optional.Downloader
20.00%

Agnitum Outpost
Riskware.Agent
15.00%

Avira AntiVirus
APPL/Downloader.Gen4, APPL/Downloader.Gen8
15.00%

AVG
Adware BundleApp_r
10.00%

K7 AntiVirus
Adware
10.00%

IKARUS anti.virus
PUA.Expressdownloader
10.00%

NANO AntiVirus
Riskware.Win32.Downware.dewbzs
10.00%

Zillya! Antivirus
Downloader.Agent.Win32.221440
10.00%

MicroWorld eScan
Gen:Variant.Application.Bundler.24
10.00%

F-Prot
W32/A-42de288b
10.00%

Bitdefender
Gen:Variant.Application.Bundler.24
10.00%

The domain dll513.webfilebase.biz has been seen to resolve to the following IP address.

September 28, 2014

File downloads found at URLs served by dll513.webfilebase.biz.

20 / 68    (Adware)
http://dll513.webfilebase.biz/.../lLoDK0uK477rSlauk=  (nikon_capture_nx2_2.2.4_serial_maker_downloader.exe)