skypemoticonscomplete.com

PROTECTSERVICE, LTD.

Domain Information

The domain skypemoticonscomplete.com registered by PROTECTSERVICE, LTD. was initially registered in February of 2014 through EVOPLUS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Registrar:
EVOPLUS LTD

Server location:
Dublin City, Ireland (IE)

Create date:
Monday, February 3, 2014

Expires date:
Friday, February 3, 2017

Updated date:
Thursday, February 4, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer.N, PUP.Installer.EliDahan.K, PUP.OlehAleksyuk.N, Threat.Win.Reputation.IMP, Adware.WebPick.Installer (M), Adware.FreeWorldApp.Installer (M), PUP.OlehAlek (M), Adware.BlueOcea.Installer (M), Adware (M)
100.00%

Kaspersky
Trojan.Win32.AntiFW, not-a-virus:AdWare.Win32.MultiPlug
41.18%

McAfee
PUP-FHQ, PUP-FMK, PUP-FHQ!D6BB6F2CE8EA, Artemis!A062939F6B2F, MultiPlug, PUP-FED!2FED3C1F51F6
41.18%

Malwarebytes
PUP.Optional.Installrex, PUP.Optional.InstalRex, PUP.Optional.InstalleRex, PUP.Optional.MultiPlug, PUP.Optional.Multiplug
41.18%

NANO AntiVirus
Riskware.Win32.InfoLeak.cvgqot, Riskware.Win32.MultiPlug.dfjscb, Trojan.Win32.XPACK.denqep
41.18%

Comodo Security
Application.Win32.InstalleRex.KG, Application.Win32.MultiPlug.PNU
41.18%

G Data
Win32.Application.InstalleRex, Gen:Variant.Kazy.324119, Trojan.Generic.11479591, Trojan.Proxy.MUS, Trojan.Generic.11664247
41.18%

MicroWorld eScan
Gen:Variant.Kazy.324119, Trojan.Generic.11479591, Trojan.Proxy.MUS, Trojan.Generic.11664247, Gen:Variant.Graftor.154530
41.18%

Bitdefender
Gen:Variant.Kazy.324119, Trojan.Generic.11479591, Trojan.Proxy.MUS, Trojan.Generic.11664247, Gen:Variant.Graftor.154530
41.18%

Lavasoft Ad-Aware
Gen:Variant.Kazy.324119, Trojan.Generic.11479591, Trojan.Proxy.MUS, Trojan.Generic.11664247, Gen:Variant.Graftor.154530
41.18%

Emsisoft Anti-Malware
Gen:Variant.Kazy.324119, Trojan.Generic.11479591, Trojan.Proxy.MUS, Trojan.Generic.11664247, Gen:Variant.Graftor.154530
41.18%

VIPRE Antivirus
Threat.4150696, Threat.4753027, Trojan.Win32.Generic
35.29%

K7 AntiVirus
Unwanted-Program , Trojan
35.29%

Avira AntiVirus
TR/Kazy.324119.28, Adware/InstallRex.A.3, Adware/MultiPlug.aoa, Adware/MultiPlug.bfp, Adware/InstallRex.A.4, TR/Crypt.XPACK.Gen
35.29%

Sophos
InstallRex, MultiPlug
35.29%

The domain skypemoticonscomplete.com has been seen to resolve to the following 4 IP addresses.

ec2-54-72-9-115.eu-west-1.compute.amazonaws.com
February 12, 2016

August 11, 2015

August 1, 2014

August 1, 2014

File downloads found at URLs served by skypemoticonscomplete.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

13 / 68    (Adware)

24 / 68    (PUP)

14 / 68    (Adware)

1 / 68      (Adware)

36 / 68    (Adware)

25 / 68    (Adware)

14 / 68    (Adware)
http://skypemoticonscomplete.com/.../Setup-seFS.exe  (a062939f6b2f759764d2b9e00857cfdc)

36 / 68    (Adware)

24 / 68    (Adware)

24 / 68    (Adware)

The following 279 files have been seen to comunicate with skypemoticonscomplete.com in live environments.

 
Latest 20 of 293 files

URL:
http://skypemoticonscomplete.com/

Title:
“skypemoticonscomplete.com”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx