www-squid.cluster12.fb-hosting-apps.com

PERFECT PRIVACY, LLC  (Proxy Registrant)

Domain Information

The domain www-squid.cluster12.fb-hosting-apps.com is registered by proxy through DOMAIN STOPOVER LLC and was originally registered in March of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
DOMAIN STOPOVER LLC

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Wednesday, March 23, 2016

Expires date:
Thursday, March 23, 2017

Updated date:
Wednesday, March 23, 2016

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Ukra2006.w, PUP.Installer.Ukra2006.p, PUP.Installer.Ukra2006.s, PUP.Installer.Ukra2006.?, PUP.Installer.Ukra2006.t, Threat.Win.Reputation.IMP, PUP.Amonetize.Ukra2006.Bundler (M), PUP.Amonetize (M)
100.00%

Sophos
Amonetize, Amonetizer
78.79%

AVG
Ukra, Generic, Adware BundleApp.CUB
78.79%

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
75.76%

ESET NOD32
Win32/Amonetize.BT (variant), Win32/Amonetize.BW (variant), Win32/Amonetize.BY (variant)
75.76%

Baidu Antivirus
Adware.Win32.Amonetize
72.73%

Dr.Web
Adware.Downware.8798, Adware.Downware.8818, Adware.Downware.8868, Adware.Downware.8860
69.70%

AhnLab V3 Security
PUP/Win32.Amonetize
69.70%

Avira AntiVirus
ADWARE/Adware.Gen4, Adware/Amonetize.519376.14, Adware/Amonetize.519376.24, Adware/Amonetize.519888.7, Adware/Amonetize.kpa
66.67%

NANO AntiVirus
Riskware.Win32.Downware.dgtmls, Riskware.Win32.Downware.dgsnhp, Riskware.Win32.Downware.dhaxhs, Riskware.Win32.Downware.dgzodg
60.61%

McAfee
Artemis!7C254E3442E5, Artemis!4DEA3BC51530, Artemis!F1BEDD9E1845, Artemis!B7855FEEC668, Artemis!E8EF27780FC3, Artemis!4B202011C182, Artemis!C22B3C7EB41F, Artemis!86834281A11C, Artemis!7861591E6CE3
60.61%

Malwarebytes
PUP.Optional.Amonetize, PUP.Optional.Bundler
57.58%

Fortinet FortiGate
Riskware/Amonetize, Adware/Amonetize
42.42%

MicroWorld eScan
Gen:Variant.Kazy.472536, Gen:Variant.Graftor.161218, Gen:Variant.Application.Bundler.Amonetize.15, Gen:Variant.Adware.Graftor.167075, Gen:Variant.Application.Bundler.Amonetize.18
33.33%

Bitdefender
Gen:Variant.Kazy.472536, Gen:Variant.Graftor.161610, Gen:Variant.Application.Bundler.Amonetize.15, Gen:Variant.Adware.Graftor.167075
33.33%

The domain www-squid.cluster12.fb-hosting-apps.com has been seen to resolve to the following 6 IP addresses.

July 20, 2016

April 12, 2016

ns1.ibspark.com
January 27, 2016

unallocated.barefruit.co.uk
May 3, 2015

October 20, 2014

October 20, 2014

File downloads found at URLs served by www-squid.cluster12.fb-hosting-apps.com.

 
Latest 30 of 60 download URLs

The following 372 files have been seen to comunicate with www-squid.cluster12.fb-hosting-apps.com in live environments.

 
Latest 20 of 384 files

URL:
http://www-squid.cluster12.fb-hosting-apps.com/

Title:
“fb-hosting-apps.com”

Web server:
nginx