plantsvszombies.luckycitygames.com

HICHAM TIMOURI

Domain Information

The domain plantsvszombies.luckycitygames.com registered by HICHAM TIMOURI was initially registered in August of 2015 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Beauharnois, Quebec within Canada.
Registrar:
ENOM, INC.

Server location:
Quebec, Canada (CA)

Create date:
Wednesday, August 26, 2015

Expires date:
Friday, August 26, 2016

Updated date:
Monday, January 4, 2016

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Detections  (64% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/InstallMonetizer.AN potentially unwanted application, Win32/Sality.NBA virus
61.11%

avast!
NSIS:InstMonetizer-CA [PUP], Win32:Kukacka, Win32:SaliCode, Win32:Sality, Win32:Evo-gen [Susp]
55.56%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A, Threat.Undefined
38.89%

Reason Heuristics
PUP.InstallMonetizer.ET (M), Threat.Win.Reputation.IMP
38.89%

F-Prot
W32/Sality.gen2, W32/Sality.E.gen
27.78%

VIPRE Antivirus
Threat.4150696, Threat.4721115
22.22%

Dr.Web
Win32.Sector.30
22.22%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
16.67%

Kaspersky
not-a-virus:AdWare.Win32.InstallMonster, Virus.Win32.Sality
16.67%

Emsisoft Anti-Malware
Win32.Sality
16.67%

AVG
Win32/Sality
16.67%

F-Secure
Application:W32/Generic.70053c248f!Online, Win32.Sality.3
11.11%

ESET NOD32
Win32/InstallMonetizer.AN potentially unwanted
11.11%

McAfee
Trojan.Artemis!52EA49057087
11.11%

Norman
Win32.Sality.3
11.11%

The domain plantsvszombies.luckycitygames.com has been seen to resolve to the following 2 IP addresses.

February 6, 2016

node5.heberfacile.net
January 4, 2016

File downloads found at URLs served by plantsvszombies.luckycitygames.com.

1 / 68      (inconclusive)

7 / 68      (Infected)

URL:
http://plantsvszombies.luckycitygames.com/

Title:
“Index of /”

Web server:
Apache