www.zfiramnel.info

nik kik

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GoDaddy.com, LLC

Server location:
Arizona, United States (US)

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.InstallCore.Internet.Installer.Meta (M), PUP.InstallCore.AFF.Installer.Meta (M), PUP.installCore (M), PUP.InstallCore.S (M), PUP.installCore.Program.Installer.Meta (M), PUP.InstallCore.RES (M), PUP.InstallCore.AFF (M), PUP.InstallCore (M)
83.87%

VIPRE Antivirus
Threat.4788237
16.13%

Dr.Web
Trojan.InstallCore.60
9.68%

ESET NOD32
Win32/InstallCore.ADX.gen potentially unwanted application
9.68%

G Data
Win32.Application.InstallCore.CZ
6.45%

ESET NOD32
Win32/InstallCore.XB potentially unwanted (variant)
6.45%

avast!
Trojan-gen
3.23%

Avira AntiVirus
PUA/InstallCore.A.2387
3.23%

AhnLab V3 Security
PUP/Win32.InstallCore
3.23%

herdProtect (fuzzy)
a variant of 68cdd6c85f1d9e9c290613ed4c0fd8e2c07f7330
3.23%

NANO AntiVirus
Riskware.Win32.InstallCore.dqheru
3.23%

Comodo Security
Application.Win32.InstallCore.DAT
3.23%

The domain www.zfiramnel.info has been seen to resolve to the following 5 IP addresses.

ip-50-63-202-47.ip.secureserver.net
February 13, 2016

ec2-107-23-41-125.compute-1.amazonaws.com
December 23, 2015

ec2-54-236-186-201.compute-1.amazonaws.com
December 23, 2015

ec2-52-22-88-81.compute-1.amazonaws.com
December 23, 2015

ec2-54-164-240-249.compute-1.amazonaws.com
July 16, 2015

File downloads found at URLs served by www.zfiramnel.info.

1 / 68      (PUP)

The following 4 files have been seen to comunicate with www.zfiramnel.info in live environments.

URL:
http://www.zfiramnel.info/

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)