m.ahlabahla97.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain m.ahlabahla97.com is registered by proxy through ENOM, INC. and was originally registered in May of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Sherman Oaks, California within the United States which resides on the Unitas Global LLC network.
Registrar:
ENOM, INC.

Server location:
California, United States (US)

Create date:
Tuesday, May 19, 2015

Expires date:
Thursday, May 19, 2016

Updated date:
Tuesday, May 19, 2015

ASN:
AS17025 ABOVENET-CUSTOMER - Abovenet Communications, Inc,US

Root domain:

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/Adware.CouponMarvel.E application, Win32/Adware.CouponMarvel.D application, multiple threats, Win32/Adware.CouponMarvel.Q.gen application, Win32/Adware.CouponMarvel.N application
50.00%

Baidu Antivirus
Adware.Win32.CouponMarvel, Adware.Win32.PullUpdate
44.00%

Malwarebytes
PUP.Optional.TomorrowGames.A, PUP.Optional.FlashBeat, PUP.Optional.KikBlaster.A, PUP.Optional.LolliScan, PUP.Optional.CouponMarvel
36.00%

AegisLab AV Signature
Troj.Dropper.W32.StartPage
34.00%

VIPRE Antivirus
Threat.5217618, FlashBeat, Trojan.Win32.Generic, Threat.4150696
28.00%

Reason Heuristics
(M), Threat.Win.Reputation.IMP, PUP.Bundler.StartPage, PUP.Somoto.Installer (M), PUP.Somoto.SiteonSp.Bundler (M), PUP.Crossrider.Installer.Meta (M)
26.00%

Emsisoft Anti-Malware
Gen:Variant.Graftor.189558, Gen:Variant.Adware.Graftor.209181, Gen:Variant.Graftor.209003, Gen:Variant.Adware.CouponMarvel
24.00%

Microsoft Security Essentials
Adware:Win32/Putalol, Threat.Undefined
22.00%

Kaspersky
UDS:DangerousObject.Multi.Generic
20.00%

ESET NOD32
Win32/Adware.CouponMarvel, Win32/Adware.CouponMarvel.Q.gen (variant)
20.00%

MicroWorld eScan
Gen:Variant.Adware.Graftor.209181, Gen:Variant.Graftor.209003, Gen:Variant.Adware.CouponMarvel.2, Trojan.GenericKD.2660892, Application.Generic.1488907, Gen:Variant.Zusy.158413
16.00%

Arcabit
Trojan.Adware.Graftor.D3311D, Trojan.Graftor.D3306B, Trojan.Adware.CouponMarvel.2, Trojan.Generic.D289A1C, Trojan.Generic.D28F799
16.00%

Bitdefender
Gen:Variant.Adware.Graftor.209181, Gen:Variant.Graftor.209003, Gen:Variant.Adware.CouponMarvel.2, Trojan.GenericKD.2660892
16.00%

G Data
Gen:Variant.Adware.Graftor.209181, Gen:Variant.Graftor.209003, Gen:Variant.Adware.CouponMarvel, Trojan.GenericKD.2660892
16.00%

IKARUS anti.virus
PUA.CouponMarvel
14.00%

The domain m.ahlabahla97.com has been seen to resolve to the following IP address.

3-125-232-198.static.unitasglobal.net
January 4, 2016

File downloads found at URLs served by m.ahlabahla97.com.

6 / 68      (PUP)

4 / 68      (PUP)
http://m.ahlabahla97.com/Kikblaster/.../Setup.exe  (88d263b87ebc210211e42695b81b47d0)

3 / 68      (PUP)

4 / 68      (PUP)
http://m.ahlabahla97.com/TomorrowGames/.../Setup.exe  (4c965e9da89be9a34301b598eb9378bf)

0 / 68
http://m.ahlabahla97.com/LolliScan/.../Setup.exe  (8a4f08aa5f031220de7438574677d627)

4 / 68      (PUP)
http://m.ahlabahla97.com/EpsanDrive/.../Setup.exe  (f7be9246a2c4b7b09d22ef58774a174e)

5 / 68      (PUP)

4 / 68      (PUP)

3 / 68      (PUP)

9 / 68      (PUP)

10 / 68    (PUP)
http://m.ahlabahla97.com/FlashBeat/.../Setup.exe  (48437c4ae9212d08ccb028228cf4c522)

5 / 68      (PUP)
http://m.ahlabahla97.com/LolyKey/.../Setup.exe  (e8f6252485d20b18846fa76ef3a4cd2c)

2 / 68      (Malware)

3 / 68      (PUP)
http://m.ahlabahla97.com/FlashBeat/.../Setup.exe  (e69a928ee01f7427f37d4807d7ad609c)

3 / 68      (PUP)
http://m.ahlabahla97.com/TomorrowGames/.../Setup.exe  (bdb8afa3c7fb9a8a796446aa67fea208)

1 / 68      (PUP)

The following 14 files have been seen to comunicate with m.ahlabahla97.com in live environments.

URL:
http://m.ahlabahla97.com/

Web server:
NetDNA-cache/2.2