winbeginner.com
Whois Privacy Protection Service, Inc. (Proxy Registrant)
Domain Information
The domain winbeginner.com is registered by proxy through NAME.COM, INC. and was originally registered in September of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrant:
Whois Privacy Protection Service, Inc.
Server location:
Arizona, United States (US)
Create date:
Tuesday, September 9, 2014
Expires date:
Friday, September 9, 2016
Updated date:
Sunday, September 6, 2015
ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc., US
Scanner detections:
Detections (67% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.OpenCandy.Installer (L), PUP.DriverSoft.DriverIn.Installer.Meta (L)
100.00%
ESET NOD32
Win32/OpenCandy.A potentially unsafe (variant)
50.00%
Dr.Web
Adware.OpenCandy.184
50.00%
AegisLab AV Signature
Opencandy.Gen!c
50.00%
Zillya! Antivirus
Adware.BrowseFox.Win32.135086
50.00%
G Data
Win32.Application.OpenCandy
50.00%
Fortinet FortiGate
Riskware/OpenCandy
50.00%
NANO AntiVirus
Riskware.Win32.OpenCandy.dqfxyu
50.00%
Trend Micro House Call
Suspicious_GEN.F47V0506
50.00%
The domain winbeginner.com has been seen to resolve to the following 2 IP addresses.
File downloads found at URLs served by winbeginner.com.
URL:
http://winbeginner.com/
Title:
“WinBeginner - Windows Beginners Guide : Hack, Tips and Trick”
Description:
“WinBeginner.com - Windows Beginner Guide, tips and trick, software reviews and discount coupon.”
SSL certificate subject:
CN=sni26316.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated
SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB
Web server:
cloudflare-nginx