www.lgtool.net

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain www.lgtool.net is registered by proxy through REGISTRAR OF DOMAIN NAMES REG.RU LLC and was originally registered in April of 2011. The hosted servers are located in Nuremberg, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
REGISTRAR OF DOMAIN NAMES REG.RU LLC

Server location:
Bayern, Germany (DE)

Create date:
Friday, April 8, 2011

Expires date:
Saturday, April 8, 2017

Updated date:
Friday, April 8, 2016

ASN:
AS24940 HETZNER-AS Hetzner Online AG

Root domain:

Google Safe Browsing:
unwanted

Scan engine
Details
Detections

AVG
Downloader.Generic13, Win32/Heur, Win32/Sality
33.33%

ViRobot
Trojan.Win32.A.Inject.9065333, Trojan.Win32.A.Downloader.49567739
22.22%

avast!
ELF:Lootor-AB [PUP], Win32:SaliCode
22.22%

Comodo Security
UnclassifiedMalware
22.22%

Baidu Antivirus
Trojan.Win32.VB, Trojan.Win32.Themida
22.22%

ESET NOD32
Win32/Packed.Themida (variant)
22.22%

IKARUS anti.virus
Trojan.Win32.VB, Win32.Heur
22.22%

ESET NOD32
Detection.Undefined, Win32/Sality.NBA virus
22.22%

VIPRE Antivirus
Trojan.Win32.Generic
11.11%

K7 AntiVirus
Exploit
11.11%

NANO AntiVirus
Trojan.Win32.VB.bulaua
11.11%

Kaspersky
Trojan-Downloader.Win32.VB
11.11%

Agnitum Outpost
Trojan.DL.VB
11.11%

Avira AntiVirus
TR/Dldr.VB.axrl
11.11%

Microsoft Security Essentials
HackTool:AndroidOS/ZergRush.B
11.11%

The domain www.lgtool.net has been seen to resolve to the following 5 IP addresses.

February 7, 2016

February 7, 2016

May 21, 2015

May 21, 2015

static.48.29.9.176.clients.your-server.de
February 6, 2014

File downloads found at URLs served by www.lgtool.net.

0 / 68

1 / 68      (PUP)
http://www.lgtool.net/getlatest  (lgetool_258.1.exe)

0 / 68

5 / 68      (Infected)

0 / 68
http://www.lgtool.net/.../selg_drv_v2.rar  (b0bf173bbeb67161f9734a582cfd1cdc)

0 / 68
http://www.lgtool.net/.../TOP_reader_omnikey_drivers.zip  (96f8e7bc0fc3fa1abfce8e7c67c79270)

5 / 68      (inconclusive)

0 / 68
http://www.lgtool.net/.../LG_VZW_United_WHQL_v2.20.0.exe  (50cc66b984d24e5f95bdf09101097b95)

0 / 68
http://www.lgtool.net/.../lgetool_257.exe  (952283b15493a8fae6d98dcaf152fbe2)

0 / 68
http://www.lgtool.net/.../lgetool_254.exe  (5a271ed3681bb33dffebd6e24801cae1)

1 / 68
http://www.lgtool.net/.../SELG_FusionBox_V2_Drivers.exe  (a8c7cf0d535907f902b75daa6f69f8d8)

17 / 68    (PUP)
http://www.lgtool.net/.../lgetool_199.exe  (e155fa126a1548e5dfcd1cdad597d658)

0 / 68
http://www.lgtool.net/.../LeDrivers_K900.msi  (998b2509fb94e862050ac7cfad96c858)

0 / 68

0 / 68

0 / 68
http://www.lgtool.net/.../LGUnitedMobileDriverWHQL3.8.1.exe  (lgunitedmobiledriver_s4981man38ap22_ml_whql_ver_3.8.1.exe)

URL:
http://www.lgtool.net/

Google Analytics:
UA-451888

Title:
“Universal service tool: unlock & repair LG phones with LGTooL!”

Description:
“LGETool software support and service site. Repair, unlock and flash LG phones with LGTOOL!”

SSL certificate subject:
CN=sni235838.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx (PHP/5.4.4-14+deb7u7)

Facebook:
Likes:  81
Shares:  190
Comments:  71

Statistics are for the previous month.