toolkit.shieldapps.info

ACC Ventures llc

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GoDaddy.com, LLC

Server location:
Arizona, United States (US)

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC

Root domain:

Scanner detections:
Detections  (78% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.VastTechSupport.R, PUP.Installer.VerticalPCSolutions.Q, PUP.Installer.VastTechSupport.V, PUP.Sensei.RegClean.Optional.Installer.Meta (L)
77.78%

Trend Micro House Call
Suspicious_GEN.F47V0713
11.11%

Zillya! Antivirus
Trojan.DoctorAntivirus.Win32.8
11.11%

ESET NOD32
MSIL/Rebrand.LittleRegClean.A potentially unwanted (variant)
11.11%

The domain toolkit.shieldapps.info has been seen to resolve to the following IP address.

p3nlhg230c1230.shr.prod.phx3.secureserver.net
May 31, 2014

File downloads found at URLs served by toolkit.shieldapps.info.

1 / 68      (inconclusive)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://toolkit.shieldapps.info/.../PCSpeedUpMDSetup.exe  (279cbb061e99c6f9b5ab5115b379b7a2)

1 / 68      (PUP)
http://toolkit.shieldapps.info/.../PCSpeedUpMDSetup.exe  (9c4317a3bbeebe6e9e23307c4e1871ca)

2 / 68      (PUP)

1 / 68      (PUP)
http://toolkit.shieldapps.info/.../OMGSpeedMyPCSetup.exe  (45416fc507b6de62328240a948181572)

The following 4 files have been seen to comunicate with toolkit.shieldapps.info in live environments.

URL:
http://toolkit.shieldapps.info/

Title:
“SHIELD Apps”

Web server:
Microsoft-IIS/8.5 (ASP.NET) (Version: 4.0.30319)