The domain webprotectionfree.com is registered by proxy through GODADDY.COM, LLC and was originally registered in January of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrant:
Domains By Proxy, LLC
Registrar:
GODADDY.COM, LLC
Server location:
Noord-Holland, Netherlands (NL)
Create date:
Thursday, January 15, 2015
Expires date:
Sunday, January 15, 2017
Updated date:
Saturday, January 16, 2016
ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US
Google Safe Browsing:
unwanted
Scanner detections:
Detections (96% detected)
Scan engine
Details
Detections
Reason Heuristics
(M), PUP.OffToUp.Installer (M), Adware.Offer.Bundle.SLI.Installer.Meta (M), Adware.Bundle.SLI.Installer.Meta (M), PUP.EasyVpn.Installer (M), Adware.Downloader.GuideSty.Installer.Meta (M), PUP.DefenseM.Installer (M), PUP (M)
79.17%
avast!
Win32:Malware-gen, Win32:Dropper-gen [Drp], Rootkit-gen [Rtk], Win32:Adware-gen [Adw], Win32:SaliCode
20.83%
Kaspersky
Trojan-Downloader.Win32.Genome, UDS:DangerousObject.Multi.Generic, Virus.Win32.Sality
12.50%
ESET NOD32
Win32/Adware.Similagro.J application, Detection.Undefined, Win32/Adware.Offtoup.A application, Win32/Sality.NBA virus
12.50%
McAfee
Artemis!80764229A410, Artemis!152B054C00FC, RDN/Generic Downloader.x!nk, RDN/Generic PUP.x!cxd, Program.Artemis!016F5B55D05A
10.42%
Norman
Downloader, Win32.Sality.3
10.42%
Trend Micro House Call
Suspicious_GEN.F47V0330, Suspicious_GEN.F47V0402, Suspicious_GEN.F47V0428, Suspicious_GEN.F47V0429
10.42%
Dr.Web
Trojan.DownLoader13.14263, Adware.Similar.12, Trojan.DownLoader19.26360, Win32.Sector.30
10.42%
Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
8.33%
Baidu Antivirus
Adware.Win32.Genome, Adware.Win32.InstallNsis
8.33%
Panda Antivirus
Generic Suspicious, PUP/WebProtect
8.33%
Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen, Win32/Trojan.Downloader.025, Win32/Trojan.Multi.daf
8.33%
herdProtect (fuzzy)
a variant of 67445bc21607bedc545ad37682eb97085066f518, a variant of 92b83bcf905b5a2cb51faa18dd1e8551f2781906
6.25%
VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696, Threat.4721115
6.25%
Microsoft Security Essentials
Worm:Win32/NeksMiner.A, Threat.Undefined
4.17%
The domain webprotectionfree.com has been seen to resolve to the following IP address.
37.58.109.2-static.reverse.softlayer.com
July 1, 2015
File downloads found at URLs served by webprotectionfree.com.
The following 5 files have been seen to comunicate with webprotectionfree.com in live environments.
URL:
http://webprotectionfree.com/
Title:
“Welcome to our website!”
Web server:
nginx/1.4.6 (Ubuntu)