The domain downprov.milordisback.com registered by Whois Privacy Corp. was initially registered in January of 2015 through TLD REGISTRAR SOLUTIONS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network.
Registrant:
Whois Privacy Corp.
Registrar:
TLD REGISTRAR SOLUTIONS LTD
Server location:
Dublin City, Ireland (IE)
Create date:
Friday, January 16, 2015
Expires date:
Monday, January 16, 2017
Updated date:
Sunday, January 17, 2016
ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US
Scanner detections:
Detections (85% detected)
Scan engine
Details
Detections
VIPRE Antivirus
Threat.4657539, Trojan.Win32.Generic.pak!cobra
92.59%
Comodo Security
Application.Win32.LoadMoney.IARS, ApplicUnwnt
74.07%
AhnLab V3 Security
PUP/Win32.Amonetize
70.37%
Baidu Antivirus
Adware.Win32.Amonetize, PUA.Win32.Amonetize
70.37%
avast!
Win32:Rootkit-gen [Rtk], Malware-gen, Adware-gen [Adw], Win32:Malware-gen, Win32:Adware-gen [Adw], Win32:Trojan-gen
66.67%
ESET NOD32
Win32/Amonetize.DK potentially unwanted
62.96%
Trend Micro House Call
Suspicious_GEN.F47V0130, Suspicious_GEN.F47V0129, TROJ_GEN.R03EC0OBD15, TROJ_GEN.R0C1H05BD15, TROJ_GEN.R02KC0OBD15, TROJ_GEN.R047C0OBL15
59.26%
Sophos
Generic PUA PD, Generic PUA IF, Generic PUA EL, Amonetize, Generic PUA JC, Generic PUA ED, Generic PUA NP, Generic PUA IA
51.85%
Kaspersky
UDS:DangerousObject.Multi.Generic, not-a-virus:AdWare.Win32.Amonetize
48.15%
McAfee
Artemis!5DC3C04DB619, Artemis!A4D54E6426FB, Artemis!AE69FE54560B, RDN/Generic.hra!ce, RDN/Generic PUP.x!c2e, RDN/Generic PUP.x!c2k, RDN/Generic.dx!djf
44.44%
NANO AntiVirus
Trojan.Nsis.Amonetize.dnxabb
44.44%
Panda Antivirus
Generic Suspicious, Trj/CI.A
40.74%
Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
37.04%
Reason Heuristics
PUP.Amonetize (M), Adware.Amonetize.ET (M)
37.04%
G Data
Win32.Application.Agent.RJX8MB, Win32.Application.Agent.7FQLHQ, Win32.Application.Agent.B0B9TN, Win32.Application.Agent.UJ6ZV2
29.63%
The domain downprov.milordisback.com has been seen to resolve to the following 3 IP addresses.
ns1.ibspark.com
February 16, 2016
File downloads found at URLs served by downprov.milordisback.com.
Latest 30 of 34 download URLs
The following 142 files have been seen to comunicate with downprov.milordisback.com in live environments.
URL:
http://downprov.milordisback.com/
Google Analytics:
UA-48689684
Related Domains
30 of 618 related domains