installer.manycams.com

Visicom Media Inc.

Domain Information

The domain installer.manycams.com registered by Visicom Media Inc. was initially registered in March of 2006 through DNC HOLDINGS, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Los Angeles, California within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
DNC HOLDINGS, INC.

Server location:
California, United States (US)

Create date:
Wednesday, March 22, 2006

Expires date:
Monday, March 22, 2021

Updated date:
Thursday, October 15, 2015

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.VisicomMedia.T, PUP.Visicom.ManyCam (L), PUP.Visicom.VisicomMedia.Installer (M)
100.00%

Dr.Web
Tool.InstallToolbar.179, Tool.InstallToolbar.174
50.00%

Bkav FE
W32.HfsAdware
25.00%

Trend Micro House Call
Suspicious_GEN.F47V0429
25.00%

ESET NOD32
Win32/Toolbar.Visicom.E potentially unwanted (variant)
25.00%

Agnitum Outpost
PUA.Toolbar.Visicom
25.00%

AVG
Generic
25.00%

The domain installer.manycams.com has been seen to resolve to the following 2 IP addresses.

March 3, 2016

March 3, 2016

File downloads found at URLs served by installer.manycams.com.

1 / 68      (PUP)
http://installer.manycams.com/.../registry_writter.exe  (ef82688f26d3a4f476272c766bb15564)

5 / 68      (PUP)

4 / 68      (PUP)

URL:
http://installer.manycams.com/

SSL certificate subject:
CN=ssl340674.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx