ozelindir.com

PERFECT PRIVACY, LLC  (Proxy Registrant)

Domain Information

The domain ozelindir.com is registered by proxy through DUCKBILLEDDOMAINS.COM LLC and was originally registered in December of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Registrar:
DUCKBILLEDDOMAINS.COM LLC

Server location:
Quebec, Canada (CA)

Create date:
Monday, December 7, 2015

Expires date:
Wednesday, December 7, 2016

Updated date:
Monday, December 7, 2015

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Navigationnetworkcolimited.W, PUP.Installer.InstallPath.BB, PUP.Navigationnetworkcolimited.K, PUP.Installer.TEHSNABSTROY.b, PUP.Installer.SystemApplet.N, PUP.Installer.FileFalcon.N, PUP.Adknowledge (M)
90.00%

Malwarebytes
PUP.Optional.PortalSepeti, PUP.Optional.Amonetize, PUP.Optional.OptimumInstaller.A, PUP.Optional.Downloader
70.00%

avast!
Win32:Adware-gen [Adw], Win32:Amonetize-CI [PUP], Win32:IBryte-DS [PUP], Win32:Amonetize-CL [PUP], Win32:Amonetize-CB [PUP]
70.00%

Bitdefender
Adware.Generic.959515, Trojan.GenericKD.1754190, Gen:Variant.Adware.Symmi.44025, Application.Bundler.Agent.B, Application.Bundler.Amonetize.N
70.00%

Lavasoft Ad-Aware
Adware.Generic.959515, Trojan.GenericKD.1754190, Gen:Variant.Adware.Symmi.44025, Application.Bundler.Agent.B, Application.Bundler.Amonetize.N
70.00%

F-Secure
Adware.Generic.959515, Trojan.GenericKD.1754190, Gen:Variant.Adware.Symmi.44025, Application.Bundler.Agent, Application.Bundler.Amonetize
70.00%

G Data
Adware.Generic.959515, Win32.Application.Amonetize, Win32.Adware.IBryte, Win32.Adware.Ibryte, Application.Bundler.Amonetize
70.00%

AhnLab V3 Security
PUP/Win32.Amonetiz, PUP/Win32.IBryte
70.00%

Qihoo 360 Security
Trojan.Generic, HEUR/Malware.QVM10.Gen, Win32/Virus.Adware.932
60.00%

Dr.Web
Adware.Downware.5488, Adware.Downware.5717, Trojan.Starman.4253, Trojan.Packed.27999, Adware.Downware.5913
60.00%

ESET NOD32
Win32/Amonetize.AX (variant), Generik.CHPRWUH (variant), Win32/Amonetize.BG (variant), Win32/Amonetize.BI (variant), Win32/Amonetize.BD (variant)
60.00%

MicroWorld eScan
Adware.Generic.959515, Trojan.GenericKD.1754190, Gen:Variant.Adware.Symmi.44025, Application.Bundler.Agent.B, Application.Bundler.Amonetize.N
60.00%

NANO AntiVirus
Riskware.Win32.Amonetize.dcblyg, Riskware.Win32.Amonetize.dcckkw, Riskware.Win32.IBryte.dbjabf, Trojan.Win32.Agent.cxjjsz
60.00%

Sophos
Generic PUA DD, Generic PUA EP, iBryte Optimum Installer, Amonetize
60.00%

Kaspersky
not-a-virus:AdWare.Win32.Amonetize, not-a-virus:AdWare.Win32.iBryte, not-a-virus:HEUR:AdWare.Win32.Amonetize
50.00%

The domain ozelindir.com has been seen to resolve to the following 2 IP addresses.

ns513839.ip-167-114-156.net
January 6, 2016

ks3268459.kimsufi.com
June 20, 2014

File downloads found at URLs served by ozelindir.com.

1 / 68      (Adware)
http://ozelindir.com/linktl  (DownloadSetup.exe)

13 / 68    (PUP)
http://ozelindir.com/linktl  (hemen.indir__7818_i961803726_il4840816.exe)

2 / 68      (Adware)
http://ozelindir.com/1080pizle  (hemen.indir.exe)

6 / 68      (Adware)
http://ozelindir.com/linktl  (bnd_100_9_2014515_1122.exe)

6 / 68      (Adware)
http://ozelindir.com/turanindira  (bnd_100_9_2014515_1122.exe)

20 / 68    (Adware)
http://ozelindir.com/linktl  (hemenindir__7818_i1065201004_il1.exe)

35 / 68    (Adware)
http://ozelindir.com/linktl  (downloadsetup.exe)

27 / 68    (Adware)
http://ozelindir.com/linktl  (downloadsetup.exe)

21 / 68    (Adware)
http://ozelindir.com/1080pizle  (herdprotect__2309_il1158974.exe)

21 / 68    (Adware)
http://ozelindir.com/linktl  (hemenindir__7818_i1022158740_il14.exe)

21 / 68    (Adware)
http://ozelindir.com/linktl  (hemenindir__7818_i1023408841_il14.exe)

2 / 68      (Adware)
http://ozelindir.com/linktl  (hemen.indir.exe)

6 / 68      (Adware)
http://ozelindir.com/turanindiru  (bnd_100_9_2014515_1122.exe)

6 / 68      (Adware)
http://ozelindir.com/toindira  (bnd_100_9_2014515_1122.exe)

6 / 68      (Adware)
http://ozelindir.com/marketa  (bnd_100_9_2014515_1122.exe)

The following 36 files have been seen to comunicate with ozelindir.com in live environments.

 
Latest 20 of 41 files

URL:
http://ozelindir.com/

Title:
“ozelindir.com - This website is for sale! - ozelindir Resources and Information.”

Description:
“This website is for sale! ozelindir.com is your first and best source for all of the information you’re looking for. From general topics to more of what you would expect to find here, ozelindir.com has it all. We hope you find what you are searc...”

Web server:
Apache (PHP/5.3.3-7+squeeze28)