lp.yougotunfriended.com
Domains By Proxy, LLC (Proxy Registrant)
Domain Information
The domain lp.yougotunfriended.com is registered by proxy through GODADDY.COM, LLC and was originally registered in April of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrant:
Domains By Proxy, LLC
Registrar:
GODADDY.COM, LLC
Server location:
Virginia, United States (US)
Create date:
Wednesday, April 22, 2015
Expires date:
Friday, April 22, 2016
Updated date:
Monday, May 11, 2015
ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Systweak.ThePhone.Installer.Meta (L), PUP.FunTechnology.Installer (M), PUP.FunTechn.Installer (M), PUP.Adknowledge.SailMach.Installer (M), PUP (M)
78.05%
Malwarebytes
PUP.Optional.UnfreindAlert.A, PUP.Optional.UnFreindAlert
53.66%
NANO AntiVirus
Riskware.Nsis.Yontoo.dqgtsc
53.66%
Avira AntiVirus
ADWARE/Adware.Gen7, ADWARE/PullUpdate.Gen7
51.22%
Dr.Web
Trojan.Yontoo.1867
39.02%
ESET NOD32
MSIL/Adware.PullUpdate.J.gen (variant)
36.59%
ESET NOD32
MSIL/Adware.PullUpdate.J.gen application
17.07%
Bkav FE
W32.HfsAdware
14.63%
Baidu Antivirus
Adware.MSIL.PullUpdate
12.20%
VIPRE Antivirus
PullUpdate
12.20%
Fortinet FortiGate
Adware/PullUpdate
7.32%
McAfee
Artemis!C5E2C4715FD5, Artemis!D82784916CE3
4.88%
avast!
Win32:Adware-gen [Adw]
4.88%
The domain lp.yougotunfriended.com has been seen to resolve to the following 4 IP addresses.
ec2-54-225-140-91.compute-1.amazonaws.com
June 30, 2015
ec2-50-19-219-4.compute-1.amazonaws.com
June 30, 2015
ec2-54-225-202-156.compute-1.amazonaws.com
June 19, 2015
ec2-23-21-156-124.compute-1.amazonaws.com
June 19, 2015
File downloads found at URLs served by lp.yougotunfriended.com.
The following 2 files have been seen to comunicate with lp.yougotunfriended.com in live environments.
URL:
http://lp.yougotunfriended.com/
Google Analytics:
UA-62895227
Network:
Amazon Web Services (AWS), running an EC2 instance
SSL certificate subject:
CN=lp.yougotunfriended.com, OU=Domain Control Validated by OneClickSSL
SSL certificate issuer:
CN=AlphaSSL CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE
Web server:
Page Server II 2.1.36 564f282 (Page Server II 2.1.36 564f282)