www.nlstorage.info

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.nlstorage.info is registered by proxy through GoDaddy.com, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GoDaddy.com, LLC

Server location:
Arizona, United States (US)

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US

Root domain:

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/SProtector (variant), Win32/Adware.SpeedingUpMyPC (variant), Win32/GenUpdater, Win32/InstallMate, Win32/Toolbar.GadgetBox
86.67%

Reason Heuristics
PUP.Installer.IncrediMail.Installer.Meta, PUP.Optional.SubeoTech.V, PUP.GenUpdater, Adware.TSULoader.Installer.Gadget.L, Adware.Gadget.Installer (M)
66.67%

Dr.Web
Tool.InstallToolbar.96, Trojan.AVKill.24563, Trojan.DownLoad3.7994, Adware.Downware.448, Trojan.AVKill.20828
46.67%

Comodo Security
ApplicUnwnt, Heur.Suspicious, UnclassifiedMalware
46.67%

McAfee
Artemis!2A959C7957EC, Artemis!1A6B07B7220F, Artemis!886535829D76, Artemis!C6E89B71DC51, Generic PUP.x!bxk, Artemis!7611441DBC9F
40.00%

MicroWorld eScan
Win32/Adware.SpeedingUpMyPC.A, Win32/GenUpdater, Win32/InstallMate.A, Win32/Toolbar.GadgetBox, Trojan.Generic.8552196
40.00%

Trend Micro House Call
TROJ_SPNR.0BC513, TROJ_GEN.F47V0501, TROJ_SPNR.0BDE13, TROJ_GEN.RCBH1KQ, TROJ_GEN.RCBZ4KM
33.33%

Malwarebytes
PUP.Optional.OptimizePro.A, Trojan.Dropper.H, PUP.Optional.BabylonSearch.A
33.33%

AhnLab V3 Security
PUP/Win32.OptimizerPro, Adware/Win32.StartPage, ASD.Prevention
33.33%

AVG
PCCleaner.B, PCCleaner.B.dropper, Skodna.Generic, Startpage
33.33%

Trend Micro
TROJ_SPNR.0BC513, TROJ_SPNR.0BDE13, ADW_DOWNWARE, TROJ_GEN.RCBZ4KM
26.67%

avast!
Win32:Dropper-gen [Drp], Win32:Adware-BCA [Adw], NSIS:SProtector-A [PUP]
26.67%

Baidu Antivirus
AdWare.Win32.SpeedingUpMyPC, Trojan.Win32.GenUpdater, Trojan.Win32.Toolbar.GadgetBox
26.67%

Fortinet FortiGate
W32/InstallMate.D, W32/Toolbar.GADGETBOX, W32/StartPage.BAKO!tr
26.67%

Boost by Reason
Optional.SubeoTech.V
20.00%

The domain www.nlstorage.info has been seen to resolve to the following 2 IP addresses.

ip-50-63-202-41.ip.secureserver.net
June 6, 2016

ec2-54-186-53-99.us-west-2.compute.amazonaws.com
April 7, 2016

File downloads found at URLs served by www.nlstorage.info.

7 / 68      (PUP)

14 / 68    (PUP)

3 / 68      (Malware)

3 / 68      (PUP)

8 / 68      (Malware)

0 / 68

10 / 68    (PUP)

8 / 68      (PUP)
http://www.nlstorage.info/installmate/.../agent_setup.exe  (59cbb0588b6ec646710ebc98b5fa6afa)

1 / 68      (Adware)

4 / 68      (PUP)
http://www.nlstorage.info/installmate/.../updater.exe  (2096b76b1a5d4e5ce2bcb19c0fada911)

9 / 68      (PUP)

6 / 68      (PUP)
http://www.nlstorage.info/installmate/.../gadgetbox.exe  (af9b8ae40b12c12377364183f402517d)

25 / 68    (PUP)

16 / 68    (Adware)

5 / 68      (PUP)

11 / 68    (PUP)
http://www.nlstorage.info/installmate/.../agent_setup.exe  (641119f9e39b80e7d8c18541850139eb)

The following 10 files have been seen to comunicate with www.nlstorage.info in live environments.

30 of 43 related domains