downprov.milordisback.com

Whois Privacy Corp.

Domain Information

The domain downprov.milordisback.com registered by Whois Privacy Corp. was initially registered in January of 2015 through TLD REGISTRAR SOLUTIONS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network.
Registrar:
TLD REGISTRAR SOLUTIONS LTD

Server location:
Dublin City, Ireland (IE)

Create date:
Friday, January 16, 2015

Expires date:
Monday, January 16, 2017

Updated date:
Sunday, January 17, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (85% detected)

Scan engine
Details
Detections

VIPRE Antivirus
Threat.4657539, Trojan.Win32.Generic.pak!cobra
92.59%

Comodo Security
Application.Win32.LoadMoney.IARS, ApplicUnwnt
74.07%

AhnLab V3 Security
PUP/Win32.Amonetize
70.37%

Baidu Antivirus
Adware.Win32.Amonetize, PUA.Win32.Amonetize
70.37%

avast!
Win32:Rootkit-gen [Rtk], Malware-gen, Adware-gen [Adw], Win32:Malware-gen, Win32:Adware-gen [Adw], Win32:Trojan-gen
66.67%

ESET NOD32
Win32/Amonetize.DK potentially unwanted
62.96%

Trend Micro House Call
Suspicious_GEN.F47V0130, Suspicious_GEN.F47V0129, TROJ_GEN.R03EC0OBD15, TROJ_GEN.R0C1H05BD15, TROJ_GEN.R02KC0OBD15, TROJ_GEN.R047C0OBL15
59.26%

Sophos
Generic PUA PD, Generic PUA IF, Generic PUA EL, Amonetize, Generic PUA JC, Generic PUA ED, Generic PUA NP, Generic PUA IA
51.85%

Kaspersky
UDS:DangerousObject.Multi.Generic, not-a-virus:AdWare.Win32.Amonetize
48.15%

McAfee
Artemis!5DC3C04DB619, Artemis!A4D54E6426FB, Artemis!AE69FE54560B, RDN/Generic.hra!ce, RDN/Generic PUP.x!c2e, RDN/Generic PUP.x!c2k, RDN/Generic.dx!djf
44.44%

NANO AntiVirus
Trojan.Nsis.Amonetize.dnxabb
44.44%

Panda Antivirus
Generic Suspicious, Trj/CI.A
40.74%

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
37.04%

Reason Heuristics
PUP.Amonetize (M), Adware.Amonetize.ET (M)
37.04%

G Data
Win32.Application.Agent.RJX8MB, Win32.Application.Agent.7FQLHQ, Win32.Application.Agent.B0B9TN, Win32.Application.Agent.UJ6ZV2
29.63%

The domain downprov.milordisback.com has been seen to resolve to the following 3 IP addresses.

ns1.ibspark.com
February 16, 2016

May 4, 2015

May 4, 2015

File downloads found at URLs served by downprov.milordisback.com.

2 / 68      (PUP)
http://downprov.milordisback.com/p/.../young jeezy flexin_10924_i23875392_il345.exe  (driver laptop hp pavilion dv3_10924_i23875109_il345.exe)

7 / 68      (PUP)

1 / 68      (inconclusive)
http://downprov.milordisback.com/p/.../idt audio for vista_10924_i23770055_il345.exe  (hazard and perception test_10924_i23773291_il345.exe)

1 / 68      (inconclusive)
http://downprov.milordisback.com/p/.../php5 for dummies pdf_10924_i24109397_il345.exe  (registry fix full version_10924_i24104599_il345.exe)

2 / 68
http://downprov.milordisback.com/p/.../cs source no steam full_10924_i23523769_il345.exe  (sparktrust pc cleaner plus license keygen_10924_i23528872_il345.exe)

18 / 68    (PUP)

2 / 68
http://downprov.milordisback.com/p/.../gta romania v2 tpb_10924_i23523978_il345.exe  (sparktrust pc cleaner plus license keygen_10924_i23528872_il345.exe)

6 / 68      (PUP)
http://downprov.milordisback.com/p/.../gta sa ps2 superman mod_10924_i23597342_il345.exe  (lacrim né pour mourir téléchargement_10924_i23598371_il345.exe)

14 / 68    (PUP)

15 / 68    (PUP)
http://downprov.milordisback.com/p/.../bleach english dub_10924_i23871287_il345.exe  (ics rom for toshiba thrive_10924_i23872593_il345.exe)

10 / 68    (PUP)

6 / 68      (PUP)
http://downprov.milordisback.com/p/.../change management pdf_10924_i23600323_il345.exe  (lacrim né pour mourir téléchargement_10924_i23598371_il345.exe)

10 / 68    (PUP)

17 / 68    (PUP)

9 / 68      (PUP)

12 / 68    (PUP)

7 / 68      (PUP)

8 / 68      (PUP)

 
Latest 30 of 34 download URLs

The following 142 files have been seen to comunicate with downprov.milordisback.com in live environments.

 
Latest 20 of 154 files

URL:
http://downprov.milordisback.com/

Google Analytics:
UA-48689684

Title:
“milordisback.com”

Web server:
nginx

30 of 618 related domains