nhsdr.2rwofu74.com

Whois Privacy Protection Service, Inc.  (Proxy Registrant)

Domain Information

The domain nhsdr.2rwofu74.com is registered by proxy through NAME.COM, INC. and was originally registered in March of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Kirkland, Washington within the United States which resides on the eNom, Incorporated network.
Registrar:
NAME.COM, INC.

Server location:
Washington, United States (US)

Create date:
Friday, March 20, 2015

Expires date:
Monday, March 20, 2017

Updated date:
Friday, April 15, 2016

ASN:
AS21740 ENOMAS1 - eNom, Incorporated,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Trojan.GenericKD.2246144
100.00%

McAfee
Artemis!8874FD632766
100.00%

Malwarebytes
PUP.Optional.MixVideoPlayer.A
100.00%

K7 AntiVirus
Trojan
100.00%

Trend Micro House Call
Suspicious_GEN.F47V0324
100.00%

avast!
Win32:Dropper-gen [Drp]
100.00%

Lavasoft Ad-Aware
Trojan.GenericKD.2246144
100.00%

F-Secure
Trojan.GenericKD.2246144
100.00%

Dr.Web
Trojan.DownLoader12.48445
100.00%

Avira AntiVirus
TR/Confuser.13821555
100.00%

ESET NOD32
MSIL/Packed.Confuser.J suspicious (variant)
100.00%

Baidu Antivirus
PUA.MSIL.NewPlayer
100.00%

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
100.00%

The domain nhsdr.2rwofu74.com has been seen to resolve to the following IP address.

rc2.sjl01.dmtracker.com
April 22, 2016

File downloads found at URLs served by nhsdr.2rwofu74.com.

13 / 68    (PUP)
http://nhsdr.2rwofu74.com/.../MixVideoPlayerSetup.exe  (8874fd632766712a6c0e0a3195c60fa5)

The following 35 files have been seen to comunicate with nhsdr.2rwofu74.com in live environments.

 
Latest 20 of 47 files

URL:
http://nhsdr.2rwofu74.com/

Google Analytics:
UA-2249740

Title:
“2Rwofu74.com”

Description:
“Find Cash Advance, Debt Consolidation and more at 2Rwofu74.com. Get the best of Insurance or Free Credit Report, browse our section on Cell Phones or learn about Life Insurance. 2Rwofu74.com is the site for Cash Advance.”

Web server:
Microsoft-IIS/8.5 (ASP.NET) (Version: 4.0.30319)

30 of 685 related domains