The domain www.getallfilesnow.com registered by Whois Privacy Corp. was initially registered in November of 2014 through TLD REGISTRAR SOLUTIONS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrant:
Whois Privacy Corp.
Registrar:
TLD REGISTRAR SOLUTIONS LTD
Server location:
Northern Ireland, United Kingdom (GB)
Create date:
Thursday, November 13, 2014
Expires date:
Sunday, November 13, 2016
Updated date:
Saturday, November 14, 2015
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.VASSANAKONGSOONGNERN.Q, PUP.VASSANAKONGSOONGNERN.I, PUP.CoolMirage, PUP.CoolMirage.VASSANAKONGSOONGNERN.Installer (M)
100.00%
Dr.Web
Adware.Downware.8319, Adware.Yontoo.54
90.91%
VIPRE Antivirus
Threat.4783938, CoolMirage Ltd
90.91%
K7 AntiVirus
Adware
90.91%
Kaspersky
not-a-virus:AdWare.NSIS.Yontoo, not-a-virus:Downloader.Win32.TornTV
81.82%
G Data
NSIS.Application.Adload, Win32.Application.Agent.55DCPG
72.73%
Trend Micro House Call
Suspicious_GEN.F47V1219, Suspicious_GEN.F47V1227, Suspicious_GEN.F47V0105, Suspicious_GEN.F47V0130, Suspicious_GEN.F47V0216
54.55%
Sophos
Generic PUA HF, CoolMirage, Generic PUA OG, Generic PUA EF
54.55%
McAfee
Artemis!FBE6491D72C2, Artemis!087FE55AA17E, Artemis!CB543C48E39E, Artemis!3301566B246D, Artemis!77BB31D9AA84, Artemis!BBE6F231D778
54.55%
ESET NOD32
NSIS/TrojanDownloader.Adload.AA, NSIS/TrojanDropper.Agent.CB
54.55%
Baidu Antivirus
Adware.NSIS.Yontoo, Hacktool.Win32.TornTV, Trojan.MSIL.ShimChanger
54.55%
AhnLab V3 Security
Win-PUP/CrossRider
45.45%
Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen, Win32/Virus.Downloader.e28
36.36%
Panda Antivirus
Trj/Chgt.N, Generic Suspicious
27.27%
The domain www.getallfilesnow.com has been seen to resolve to the following 4 IP addresses.
unallocated.barefruit.co.uk
May 15, 2016
ns1.ibspark.com
November 19, 2015
ec2-50-18-180-145.us-west-1.compute.amazonaws.com
November 29, 2014
ec2-184-72-49-17.us-west-1.compute.amazonaws.com
November 29, 2014
File downloads found at URLs served by www.getallfilesnow.com.
Latest 30 of 1,063 download URLs
The following 372 files have been seen to comunicate with www.getallfilesnow.com in live environments.
URL:
http://www.getallfilesnow.com/
Title:
“getallfilesnow.com”