www.emule.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.emule.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 1999. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Paris, Ile-De-France within France which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Ile-De-France, France (FR)

Create date:
Sunday, March 21, 1999

Expires date:
Monday, March 21, 2022

Updated date:
Wednesday, September 19, 2012

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Detections  (58% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MetaInstaller.J, PUP.DescargaSegura.J, PUP.Vittalia.MetaInstaller (M), PUP.Vittalia.MetaInst.Bundler (M), Threat.Win.Reputation.IMP, PUP.Vittalia (M)
66.67%

VIPRE Antivirus
Lollipop, Vittalia Installer, Conduit, Threat.4786236, Trojan.Win32.Generic
27.78%

ESET NOD32
Win32/Adware.Lollipop, Win32/MetaInstaller, Win32/Toolbar.Conduit (variant), Win32/Toolbar.Babylon
27.78%

Dr.Web
Adware.Downware.441, Adware.Downware.1058, Adware.Conduit.35, Adware.Conduit.37
22.22%

Baidu Antivirus
Toolbar.Win32.Babylon potentially unwanted, Adware.Win32.Conduit, Trojan.Win32.Agent
22.22%

McAfee
Artemis!BB29F613FF27, Artemis!F72CAEC4C571, Trojan.Artemis!E6E05DABB404, Artemis!06FF3285C137
22.22%

Trend Micro House Call
TROJ_GEN.R0CCH01G513, TROJ_GEN.R47H1JR, TROJ_GEN.F47V0102
16.67%

ESET NOD32
Win32/Toolbar.Conduit.B potentially unwanted application, Win32/Hoax.ArchSMS.ABZ application
16.67%

Fortinet FortiGate
W32/Toolbar.BABYLON
11.11%

Vba32 AntiVirus
suspected of Archive.MailBomb, Trojan-Clicker.MSIL.Xone.de
11.11%

NANO AntiVirus
Trojan.Win32.XPACK.bdxyzi
11.11%

Microsoft Security Essentials
SoftwareBundler:Win32/Lolliport
5.56%

avast!
Win32:Toolbar-O [Adw]
5.56%

Sophos
One Installer
5.56%

Comodo Security
ApplicUnwnt.Win32.Lollipop.C
5.56%

The domain www.emule.com has been seen to resolve to the following 4 IP addresses.

ns373675.ip-94-23-250.eu
June 30, 2015

ec2-54-229-80-25.eu-west-1.compute.amazonaws.com
December 2, 2014

173.192.13.146-static.reverse.softlayer.com
August 1, 2014

173.192.13.147-static.reverse.softlayer.com
August 1, 2014

File downloads found at URLs served by www.emule.com.

1 / 68      (Adware)
http://www.emule.com/down/.../emule048a.exe  (b1299ee6b029ddf8ede07e5e097a8b75)

1 / 68      (Adware)
http://www.emule.com/down/.../emule050a.exe  (638df91a6504da8b7f4b922134023a9c)

1 / 68      (Adware)
http://www.emule.com/down/.../emuleplus12e.exe  (d158e17187b12e35c022288a71a747b4)

0 / 68
http://www.emule.com/down/.../emule050a.exe  (1b3db85def6b7224750b6644930c5d45)

0 / 68
http://www.emule.com/down/.../emule050a.exe  (0c54775dbaa7d24da9ab6749f82ceafb)

3 / 68      (Malware)
http://www.emule.com/down/.../emuleplus12e.exe  (55f0599381dd01059e03f200e09a9527)

6 / 68      (PUP)
http://www.emule.com/down/.../emule050a.exe  (06ff3285c137bfcfe8d8f47758942e4d)

0 / 68
http://www.emule.com/down/.../emule050a.exe  (41ef011d1479f9bbce2aca80af04e737)

0 / 68
https://www.emule.com/down/.../emule050a.exe  (172a95319642b17abd795106b8300bc9)

0 / 68
http://www.emule.com/server.met  (e7428a9479465ad9e708d782d4e841fa)

1 / 68      (Adware)
http://www.emule.com/down/.../emuleplus12e.exe  (ac9d60d38496ab6d4426ee7ea5bb3522)

0 / 68
http://www.emule.com/down/.../emule050a.exe  (140176d25df57b07bd201cb1767066e0)

3 / 68
http://www.emule.com/down/.../emule047c.exe  (f72caec4c5715ae021fc5786a6925f0a)

2 / 68      (Malware)
http://www.emule.com/down/.../emule050a.exe  (30505ee5c1654d6d98ffc2b8ea151166)

2 / 68      (Malware)
http://www.emule.com/down/.../emule050a.exe  (96f6a3899381654b8997c5f2d863b63b)

1 / 68
http://www.emule.com/down/.../emuleplus12e.exe  (b492495533892dacd4c2aec2127c4b32)

1 / 68      (Adware)
http://www.emule.com/down/.../emule050a.exe  (eda8c3349dc516a2ad2579681c55e86e)

1 / 68      (Adware)
http://www.emule.com/down/.../emule049c.exe  (51fe6a531fd0521d82645d5007e27a36)

1 / 68      (Adware)
http://www.emule.com/down/.../emule049a.exe  (2fbf6a1d380c30e5c819e8d1d7bb071a)

0 / 68
http://www.emule.com/down/.../emule050a.exe  (0c54775dbaa7d24da9ab6749f82ceafb)

8 / 68      (PUP)
http://www.emule.com/down/.../emule049c.exe  (bb29f613ff27b91b4c2ec544f57b9d3c)

2 / 68      (inconclusive)
http://www.emule.com/down/.../emule049a.exe  (3611b7ae38cc43aada538155c175eafa)

0 / 68
http://www.emule.com/down/.../emule050a.exe  (0c54775dbaa7d24da9ab6749f82ceafb)

0 / 68
http://www.emule.com/down/.../emule050a.exe  (210fbaab978813dfe270580e31577196)

7 / 68      (Adware)
http://www.emule.com/down/.../emule050a.exe  (0768236048855848cd0b7f0c434e57aa)

9 / 68      (PUP)
http://www.emule.com/down/.../emule050a.exe  (1bf040af888425a04f666f44f66a1f03)

3 / 68      (PUP)
http://www.emule.com/down/.../emule050a.exe  (502ea2976e1e8b1cb89b84ea2363b104)

0 / 68
http://www.emule.com/down/.../emule050a.exe  (23a6e6f9b63b90d13b9e210dc10bc6ab)

The following 16 files have been seen to comunicate with www.emule.com in live environments.

URL:
http://www.emule.com/

Google Analytics:
UA-51417028

Title:
“eMule - Download eMule for free | eMule.com”

Description:
“Download eMule for free. With eMule you can download all kinds of files for free. Movies, music, games, ebooks and software”

Web server:
Apache/2.4.7 (Ubuntu) (PHP/5.5.9-1ubuntu4.14)

Facebook:
Likes:  88
Shares:  283
Comments:  121

Statistics are for the previous month.