The domain safeserver-1.com registered by Corp New Ventures Services was initially registered in December of 2015 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in West Chester, Ohio within the United States which resides on the Level 3 Communications, Inc. network.
Registrant:
Corp New Ventures Services
Registrar:
SLOW PUTT DOMAINS LLC
Server location:
Ohio, United States (US)
Create date:
Sunday, December 27, 2015
Expires date:
Tuesday, December 27, 2016
Updated date:
Sunday, January 3, 2016
ASN:
AS30152 BEYOND-HOSTING - Beyond Hosting, LLC,US
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.FileVerified.O, PUP.VerifiedSetup.O, PUP.Installer.FileVerified.U, PUP.FileVerified.O, PUP.InstallMetrix.FileVerified (M), PUP.InstallMetrix.FileVerified.Installer (M), PUP.InstallMetrix.VerifiedSetup (M), PUP.InstallMetrix.FileVeri (M), PUP.InstallMetrix.Verified (M), PUP.InstallMetrix.Verified.Installer (M), PUP.InstallMetrix.FileVeri.Installer (M)
100.00%
avast!
Win32:Adware-gen [Adw], Win32:Rootkit-gen [Rtk], Win32:Malware-gen
66.67%
Kaspersky
not-a-virus:AdWare.Win32.InstallMonster, not-a-virus:AdWare.Win32.InstallMetrix
66.67%
NANO AntiVirus
Riskware.Win32.InstallMonster.dgppyq, Riskware.Win32.InstallMonster.dhazif, Trojan.Win32.Domaiq.dmxcza
66.67%
VIPRE Antivirus
Threat.5063683, InstallMetrix, Threat.4150696
66.67%
F-Prot
W32/A-5b646058, W32/A-215008ab, W32/S-a86f5fbc
66.67%
Agnitum Outpost
PUA.InstallMetrix
66.67%
Avira AntiVirus
Adware/AgentCV.2066560.13, Adware/InstallMonster.deih.4, Adware/InstallMonster.deih.27, Adware/InstallMonster.deih.13, Adware/InstallMonster.deih.20
66.67%
AVG
Generic, Generic5.CHSX.dropper, Adware Generic5.CHSX.dropper, Generic6
66.67%
Zillya! Antivirus
Adware.InstallMonster.Win32.32, Adware.InstallMonster.Win32.42, Adware.InstallMetrix.Win32.7
63.89%
Vba32 AntiVirus
AdWare.InstallMonster
61.11%
IKARUS anti.virus
PUA.InstallMetrix
61.11%
K7 AntiVirus
Adware , Riskware
61.11%
Clam AntiVirus
Win.Adware.Installmonster-8, Win.Adware.Installmonster-9, Win.Adware.Installmetrix-4, Win.Adware.Installmonster-15
61.11%
Dr.Web
Trojan.Domaiq.7, Trojan.Amonetize.7, Trojan.Domaiq.16, Trojan.Domaiq.110
61.11%
The domain safeserver-1.com has been seen to resolve to the following 3 IP addresses.
8-36-40-211.bhsrv.net
October 20, 2014
File downloads found at URLs served by safeserver-1.com.
The following 2 files have been seen to comunicate with safeserver-1.com in live environments.
URL:
http://safeserver-1.com/