lp.yougotunfriended.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain lp.yougotunfriended.com is registered by proxy through GODADDY.COM, LLC and was originally registered in April of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Wednesday, April 22, 2015

Expires date:
Friday, April 22, 2016

Updated date:
Monday, May 11, 2015

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Systweak.ThePhone.Installer.Meta (L), PUP.FunTechnology.Installer (M), PUP.FunTechn.Installer (M), PUP.Adknowledge.SailMach.Installer (M), PUP (M)
78.05%

Malwarebytes
PUP.Optional.UnfreindAlert.A, PUP.Optional.UnFreindAlert
53.66%

NANO AntiVirus
Riskware.Nsis.Yontoo.dqgtsc
53.66%

Avira AntiVirus
ADWARE/Adware.Gen7, ADWARE/PullUpdate.Gen7
51.22%

Dr.Web
Trojan.Yontoo.1867
39.02%

ESET NOD32
MSIL/Adware.PullUpdate.J.gen (variant)
36.59%

AVG
Generic
19.51%

ESET NOD32
MSIL/Adware.PullUpdate.J.gen application
17.07%

Bkav FE
W32.HfsAdware
14.63%

Baidu Antivirus
Adware.MSIL.PullUpdate
12.20%

VIPRE Antivirus
PullUpdate
12.20%

Fortinet FortiGate
Adware/PullUpdate
7.32%

McAfee
Artemis!C5E2C4715FD5, Artemis!D82784916CE3
4.88%

K7 AntiVirus
Adware
4.88%

avast!
Win32:Adware-gen [Adw]
4.88%

The domain lp.yougotunfriended.com has been seen to resolve to the following 4 IP addresses.

ec2-54-225-140-91.compute-1.amazonaws.com
June 30, 2015

ec2-50-19-219-4.compute-1.amazonaws.com
June 30, 2015

ec2-54-225-202-156.compute-1.amazonaws.com
June 19, 2015

ec2-23-21-156-124.compute-1.amazonaws.com
June 19, 2015

File downloads found at URLs served by lp.yougotunfriended.com.

The following 2 files have been seen to comunicate with lp.yougotunfriended.com in live environments.

URL:
http://lp.yougotunfriended.com/

Google Analytics:
UA-62895227

Network:
Amazon Web Services (AWS), running an EC2 instance

SSL certificate subject:
CN=lp.yougotunfriended.com, OU=Domain Control Validated by OneClickSSL

SSL certificate issuer:
CN=AlphaSSL CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Web server:
Page Server II 2.1.36 564f282 (Page Server II 2.1.36 564f282)