profficer.org

Natan Kelvin

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Manassas, Virginia within the United States which resides on the Leaseweb USA, Inc. network.
Registrar:
EvoPlus Ltd. (R1823-LROR)

Server location:
Virginia, United States (US)

ASN:
AS30633 LEASEWEB-US - Leaseweb USA, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.WebPick, Threat.Win.Reputation.IMP, PUP.WebPick, Threat.WebPick.RonenKvurt, PUP.WebPick.StepanRy.Bundler (M), PUP.WebPick.RonenKvu (M), PUP.WebPick.Kaydar (M), PUP (M)
100.00%

F-Secure
Gen:Variant.Adware.Mikey.7658, Gen:Variant.Adware.Kazy.552220, Gen:Variant.Adware.MPLug
36.67%

AVG
Generic, Adware Generic6, Adware Generic6.NRX, Adware Generic6.OPV, Adware Generic6.NWA, Adware Generic6.PBR, Adware Generic6.NXN
36.67%

Emsisoft Anti-Malware
Gen:Variant.Adware.Mikey.7658, Gen:Variant.Adware.Kazy.552220, Gen:Variant.Adware.MPLug.35
33.33%

Lavasoft Ad-Aware
Gen:Variant.Adware.Mikey.7658, Gen:Variant.Adware.Kazy.552220, Gen:Variant.Adware.MPLug.35
33.33%

MicroWorld eScan
Gen:Variant.Adware.Mikey.7658, Gen:Variant.Adware.Kazy.552220, Gen:Variant.Adware.MPLug.35
33.33%

Bitdefender
Gen:Variant.Adware.Mikey.7658, Gen:Variant.Adware.Kazy.552220, Gen:Variant.Adware.MPLug.35
33.33%

Avira AntiVirus
Adware/MPlug.tros, ADWARE/MultiPlug.Gen7, PUA/MultiPlug.11245, PUA/Multiplug.trov
33.33%

G Data
Gen:Variant.Adware.Mikey.7658, Gen:Variant.Adware.Kazy.552220, Gen:Variant.Adware.MPLug.35
33.33%

AhnLab V3 Security
PUP/Win32.MultiPlug
33.33%

K7 AntiVirus
Unwanted-Program
33.33%

F-Prot
W32/S-b1f91337, W32/S-05e718fa, W32/S-42f8a357, W32/S-ee49f53c
33.33%

ESET NOD32
Win32/Adware.MultiPlug.ES application, Win32/Adware.MultiPlug.EW application
30.00%

McAfee
Multiplug-FVQ, Program.Multiplug-FVQ, Program.MultiPlug-FVQ, Program.MultiPlug-FVZ
30.00%

Sophos
MultiPlug, PUA 'MultiPlug' (of type Adware)
30.00%

The domain profficer.org has been seen to resolve to the following 2 IP addresses.

ec2-54-149-36-237.us-west-2.compute.amazonaws.com
August 11, 2015

hosted-by.leaseweb.com
March 21, 2015

File downloads found at URLs served by profficer.org.

 
Latest 30 of 30 download URLs

URL:
http://profficer.org/

Title:
“download”

Web server:
openresty