www.boxore.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.boxore.com is registered by proxy through GODADDY.COM, LLC and was originally registered in June of 2011. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Le Mans, Pays De La Loire within France which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Pays De La Loire, France (FR)

Create date:
Wednesday, June 1, 2011

Expires date:
Wednesday, June 1, 2016

Updated date:
Thursday, March 14, 2013

ASN:
AS44976 HIWIT_AS AZNET s.a.r.l.,FR

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.BoxoreOU.P
100.00%

Trend Micro House Call
TROJ_GEN.F47V0509, Suspicious_GEN.F47V1107
100.00%

Dr.Web
Adware.Downware.1463
100.00%

G Data
Win32.Trojan-Dropper.BoxoreInject
100.00%

VIPRE Antivirus
Backdoor.Win32.Bifrose.fsi, Boxore
100.00%

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
100.00%

Avira AntiVirus
TR/Trash.Gen
100.00%

NANO AntiVirus
Trojan.Win32.Downware.ctonas
100.00%

Malwarebytes
PUP.Optional.SoftwareUpdate.A
100.00%

The domain www.boxore.com has been seen to resolve to the following IP address.

ns04.hiwit.net
February 4, 2016

File downloads found at URLs served by www.boxore.com.

9 / 68      (Adware)
http://www.boxore.com/partners/.../BoxoreInstaller.exe  (a0756f044fdda70afeb4949c3c45e5dd)

9 / 68      (Adware)
https://www.boxore.com/partners/.../BoxoreInstaller.exe  (4ebc401e9b17420f6ede2747e6de0196)

The following 21 files have been seen to comunicate with www.boxore.com in live environments.

 
Latest 20 of 21 files

URL:
http://www.boxore.com/

Title:
“Boxore - Logiciel Boxore”

Description:
“Boxore Télécharger gratuitement le logiciel Boxore. Bon plan du web et meilleures offres.”

SSL certificate subject:
CN=www.boxore.com, OU=Domain Control Validated - RapidSSL(R), OU=See www.rapidssl.com/resources/cps (c)14, OU=GT85384966

SSL certificate issuer:
CN=RapidSSL SHA256 CA - G3, O=GeoTrust Inc., C=US

Web server:
nginx

Facebook:
Shares:  1

Statistics are for the previous month.