framarootappdownload.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain framarootappdownload.com is registered by proxy through GODADDY.COM, LLC and was originally registered in April of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Austin, Texas within the United States which resides on the A Small Orange LLC network.
Registrar:
GODADDY.COM, LLC

Server location:
Texas, United States (US)

Create date:
Sunday, April 3, 2016

Expires date:
Monday, April 3, 2017

Updated date:
Sunday, April 3, 2016

ASN:
AS36024 COLO4-CO - Colo4, LLC, US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Android.Riskware.Agent.gXWWP
100.00%

McAfee
Android/Lotoor
100.00%

Zillya! Antivirus
Downloader.OpenConnection.JS.145274
100.00%

avast!
Android:Lootor-AC [PUP]
100.00%

Kaspersky
HEUR:Exploit.AndroidOS.Lotoor
100.00%

Bitdefender
Android.Riskware.Agent.gXWWP
100.00%

NANO AntiVirus
Trojan.Android.Agent.dcuiwc
100.00%

AegisLab AV Signature
Exploit.Androidos.Lotoor!c
100.00%

Rising Antivirus
APK:Trojan.Generic(AndrCity)!7.1762 [F]
100.00%

Lavasoft Ad-Aware
Android.Riskware.Agent.gXWWP
100.00%

Sophos
Andr/DroidRt-E
100.00%

Comodo Security
TrojWare.Android.Lotoor.~FCD
100.00%

Dr.Web
Tool.Rooter.3
100.00%

VIPRE Antivirus
Trojan.AndroidOS.Generic.A
100.00%

F-Prot
AndroidOS/Lotoor.A
100.00%

The domain framarootappdownload.com has been seen to resolve to the following IP address.

server.hostingsaving.org
June 6, 2016

File downloads found at URLs served by framarootappdownload.com.

23 / 68    (PUP)
https://framarootappdownload.com/Framaroot-1.9.3.apk  (9dc1a6770bf57142bbfb9428b3e6213e)

URL:
http://framarootappdownload.com/

Title:
“Framaroot - Download Framaroot APK for Free”

SSL certificate subject:
CN=framarootappdownload.com, OU=Domain Control Validated

SSL certificate issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc."

Web server:
Apache