webprotectionfree.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain webprotectionfree.com is registered by proxy through GODADDY.COM, LLC and was originally registered in January of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Thursday, January 15, 2015

Expires date:
Sunday, January 15, 2017

Updated date:
Saturday, January 16, 2016

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
(M), PUP.OffToUp.Installer (M), Adware.Offer.Bundle.SLI.Installer.Meta (M), Adware.Bundle.SLI.Installer.Meta (M), PUP.EasyVpn.Installer (M), Adware.Downloader.GuideSty.Installer.Meta (M), PUP.DefenseM.Installer (M), PUP (M)
79.17%

avast!
Win32:Malware-gen, Win32:Dropper-gen [Drp], Rootkit-gen [Rtk], Win32:Adware-gen [Adw], Win32:SaliCode
20.83%

Kaspersky
Trojan-Downloader.Win32.Genome, UDS:DangerousObject.Multi.Generic, Virus.Win32.Sality
12.50%

ESET NOD32
Win32/Adware.Similagro.J application, Detection.Undefined, Win32/Adware.Offtoup.A application, Win32/Sality.NBA virus
12.50%

McAfee
Artemis!80764229A410, Artemis!152B054C00FC, RDN/Generic Downloader.x!nk, RDN/Generic PUP.x!cxd, Program.Artemis!016F5B55D05A
10.42%

Norman
Downloader, Win32.Sality.3
10.42%

Trend Micro House Call
Suspicious_GEN.F47V0330, Suspicious_GEN.F47V0402, Suspicious_GEN.F47V0428, Suspicious_GEN.F47V0429
10.42%

Dr.Web
Trojan.DownLoader13.14263, Adware.Similar.12, Trojan.DownLoader19.26360, Win32.Sector.30
10.42%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
8.33%

Baidu Antivirus
Adware.Win32.Genome, Adware.Win32.InstallNsis
8.33%

Panda Antivirus
Generic Suspicious, PUP/WebProtect
8.33%

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen, Win32/Trojan.Downloader.025, Win32/Trojan.Multi.daf
8.33%

herdProtect (fuzzy)
a variant of 67445bc21607bedc545ad37682eb97085066f518, a variant of 92b83bcf905b5a2cb51faa18dd1e8551f2781906
6.25%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696, Threat.4721115
6.25%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A, Threat.Undefined
4.17%

The domain webprotectionfree.com has been seen to resolve to the following IP address.

37.58.109.2-static.reverse.softlayer.com
July 1, 2015

File downloads found at URLs served by webprotectionfree.com.

1 / 68      (Malware)

11 / 68    (PUP)

2 / 68      (false positives)

17 / 68    (PUP)

The following 5 files have been seen to comunicate with webprotectionfree.com in live environments.

URL:
http://webprotectionfree.com/

Title:
“Welcome to our website!”

Web server:
nginx/1.4.6 (Ubuntu)