i.greetingmoods.com

Greetingmoods

Domain Information

The domain i.greetingmoods.com registered by Greetingmoods was initially registered in April of 2011 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Providence, Utah within the United States which resides on the Hosting Services, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Utah, United States (US)

Create date:
Thursday, April 28, 2011

Expires date:
Friday, April 28, 2017

Updated date:
Thursday, February 11, 2016

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Funmoods.F
100.00%

Bkav FE
W32.Clod70d.Trojan
100.00%

Malwarebytes
PUP.Optional.Funmoods
100.00%

K7 AntiVirus
Trojan
100.00%

F-Prot
W32/InstallCore.G4.gen
100.00%

avast!
Win32:FunMood-A [PUP]
100.00%

Sophos
Funmoods Toolbar
100.00%

Avira AntiVirus
APPL/InstallCore.AH.31
100.00%

ESET NOD32
Win32/InstallCore
100.00%

Rising Antivirus
PE:AdWare.Win32.InstallCore.i!1075350952
100.00%

Baidu Antivirus
Adware.Win32.Agent
100.00%

The domain i.greetingmoods.com has been seen to resolve to the following 6 IP addresses.

April 18, 2016

April 18, 2016

April 18, 2016

April 18, 2016

April 18, 2016

April 18, 2016

File downloads found at URLs served by i.greetingmoods.com.

11 / 68    (PUP)
http://i.greetingmoods.com/fm/gmwbst/.../Setup.exe  (592f35f9954a7ec4c0b4985857f81ad8)

The following 4 files have been seen to comunicate with i.greetingmoods.com in live environments.

URL:
http://i.greetingmoods.com/

Web server:
nginx/1.0.10