new.getapplicationmy.info

WEB PICK - INTERNET HOLDINGS LTD

Domain Information

getapplicationmy.info is a landing page for the download and installtion of software wrapped with the WebPick Internet Holdings InstalleRex download manager which distributes adware web browser extensions and utility offers in the installer. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter. The domain is associated with the publisher WEB PICK - INTERNET HOLDINGS LTD who is located in Ramat Hasharon, Israel.
Registrar:
EvoPlus Ltd.

Server location:
Oregon, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Scanner detections:
Detections  (91% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.SergeyPetrov.I, PUP.Optional.SergeyPetrov.n, PUP.SergeyPetrov.Y, PUP.WebPick.SergeyPetrov (M), Adware.WebPick.Installer (M), PUP.WebPick.SergeyPe (M), Adware (M)
100.00%

avast!
Win32:InstalleRex-BI [PUP]
10.00%

AVG
Generic_r.HY
10.00%

Bkav FE
W32.MultiPlugAZ.Adware
10.00%

MicroWorld eScan
Gen:Variant.Adware.Dropper.101
10.00%

McAfee
PUP-FID!3EA3DA69CEC2
10.00%

Malwarebytes
PUP.Optional.MultiPlug.A
10.00%

VIPRE Antivirus
Installerex/WebPick
10.00%

K7 AntiVirus
Adware
10.00%

NANO AntiVirus
Riskware.Win32.MultiPlug.cvshxw
10.00%

F-Prot
W32/MultiPlug.C.gen
10.00%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Agent
10.00%

Bitdefender
Gen:Variant.Adware.Dropper.101
10.00%

Agnitum Outpost
PUA.MultiPlug
10.00%

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.139281
10.00%

The domain new.getapplicationmy.info has been seen to resolve to the following 2 IP addresses.

ec2-54-186-255-26.us-west-2.compute.amazonaws.com
May 21, 2014

ec2-54-201-215-30.us-west-2.compute.amazonaws.com
March 14, 2014

File downloads found at URLs served by new.getapplicationmy.info.

The following file have been seen to comunicate with new.getapplicationmy.info in live environments.