freempr13.bertrejota.com

Only contact by email, all postal mail will be rejected  (Proxy Registrant)

Domain Information

The domain freempr13.bertrejota.com is registered by proxy through SOLUCIONES CORPORATIVAS IP, SL and was originally registered in December of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Madrid, Madrid within Spain which resides on the RIPE Network Coordination Centre network.
Registrar:
SOLUCIONES CORPORATIVAS IP, SL

Server location:
Madrid, Spain (ES)

Create date:
Thursday, December 4, 2014

Expires date:
Friday, December 4, 2015

Updated date:
Friday, January 15, 2016

ASN:
AS45037 HISPAWEB-NETWORK Propelin Consulting S.L.U.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.CodeTechno.e, PUP.ClickToStart, PUP.Outbrowse.Bundler, PUP.DownloadAdmin.Bundler.Meta (M), PUP.Air Software.InstallerSetup (M), PUP.DownloadAdmin.CodeTech.Installer (M), PUP.InstallCore.FC.Installer (M), PUP.Air Software (M)
100.00%

ESET NOD32
Win32/DownloadAdmin.H potentially unwanted application, Win32/OutBrowse.BM potentially unwanted application, Win32/AirAdInstaller.E potentially unwanted application
50.00%

Dr.Web
Adware.Downware.2220, Trojan.OutBrowse.51, Adware.Iminent.4
50.00%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic, Threat.4782985
50.00%

Malwarebytes
PUP.Optional.DownloadAdmin, PUP.Optional.OutBrowse, PUP.Optional.AirInstall
50.00%

K7 AntiVirus
Unwanted-Program
50.00%

NANO AntiVirus
Riskware.Win32.Downware.djahkt, Trojan.Win32.OutBrowse.dluceg, Riskware.Win32.Iminent.djreap
50.00%

Agnitum Outpost
Riskware.Agent, PUA.OutBrowse, PUA.AirAd
50.00%

Avira AntiVirus
ADWARE/Adware.Gen, APPL/Downloader.Gen, PUA/Outbrowse.Gen, TR/Dropper.Gen
50.00%

G Data
Win32.Application.DownloadAdmin, Dropped:Application.Bundler.Outbrowse.AA, Gen:Variant.Application.Bundler.Strictor.74625
50.00%

AVG
Generic, Potentially harmful program Downloader.CVE
50.00%

F-Secure
Riskware.Dropped:Application.Bundler.Outbrowse, Riskware.Gen:Variant.Application.Bundler
50.00%

AhnLab V3 Security
PUP/Win32.Downware, PUP/Win32.OutBrowse, PUP/Win32.Installer
37.50%

IKARUS anti.virus
Trojan.Dropper, PUA.OutBrowse, PUA.AirAdInstaller
37.50%

Lavasoft Ad-Aware
Dropped:Application.Bundler.Outbrowse.AA, Gen:Variant.Application.Bundler.Strictor.74625
37.50%

The domain freempr13.bertrejota.com has been seen to resolve to the following 3 IP addresses.

May 15, 2015

January 21, 2015

January 21, 2015

File downloads found at URLs served by freempr13.bertrejota.com.

1 / 68      (Adware)

The following file have been seen to comunicate with freempr13.bertrejota.com in live environments.