www5l.incredimail.com

IncrediMail, Inc.

Domain Information

The domain www5l.incredimail.com registered by IncrediMail, Inc. was initially registered in October of 1999 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the nLayer Communications Internal/Backbone network.
Registrar:
GODADDY.COM, LLC

Server location:
New York, United States (US)

Create date:
Wednesday, October 27, 1999

Expires date:
Wednesday, January 2, 2019

Updated date:
Tuesday, November 11, 2014

ASN:
AS4436 AS-GTT-4436 - nLayer Communications, Inc.,US

Root domain:

Scanner detections:
Detections  (56% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Perion.L, PUP.Installer.Perion.T, PUP.Installer.Perion.H, PUP.Installer.Perion.S, PUP.Installer.Perion.O, PUP.Installer.BitCocktail.U, PUP.Perion.Installer.O, PUP.Installer.Perion.Q, PUP.Installer.Perion.W, PUP.IncrediMail.Installer.Installer.Meta (L), PUP.Perion.Bundler (M), PUP.Perion (M)
80.00%

Dr.Web
Tool.InstallToolbar.96, Adware.SweetIM.28, Trojan.DownLoader1.50195, Adware.IncrediMail.11, Win32.Sector.30, Adware.IncrediMail.36
53.33%

VIPRE Antivirus
Trojan.Win32.Generic, Sweetpacks/SweetIM
20.00%

Trend Micro House Call
TROJ_GEN.F47V0813, TROJ_GEN.F47V1229, TROJ_GEN.F47V1020, Suspicious_GEN.F47V0106, Suspicious_GEN.F47V0413
20.00%

ESET NOD32
Win32/Toolbar.Perion (variant), Win32/SweetIM, Win32/Toolbar.Perion.G potentially unwanted (variant)
16.67%

Baidu Antivirus
Adware.Win32.Agent, Adware.Win32.Perinet
13.33%

Kaspersky
not-a-virus:WebToolbar.Win32.Perinet
13.33%

McAfee
Artemis!127C4C5D6216, Artemis!9D1F9A726AE5, Artemis!C09AF9033508
10.00%

Malwarebytes
PUP.Optional.InstallBrain.A, PUP.Optional.Sweetpacks
10.00%

K7 AntiVirus
Unwanted-Program
10.00%

NANO AntiVirus
Trojan.Nsis.Downloader.dgzdwf, Trojan.Nsis.Toolbar.dflenu, Trojan.Win64.Generic.degcxu
10.00%

G Data
Win32.Application.Agent.AE676M, Win32.Application.Iminent
10.00%

Sophos
Generic PUA PC, Generic PUA JM
6.67%

Avira AntiVirus
Adware/Agent.3547440, Adware/Agent.4748456
6.67%

Qihoo 360 Security
Win32/Virus.WebToolbar.2ea
6.67%

The domain www5l.incredimail.com has been seen to resolve to the following 63 IP addresses.

a23-219-88-166.deploy.static.akamaitechnologies.com
August 25, 2016

a23-50-225-11.deploy.static.akamaitechnologies.com
August 23, 2016

a23-219-88-175.deploy.static.akamaitechnologies.com
August 23, 2016

a104-96-221-114.deploy.static.akamaitechnologies.com
July 24, 2016

a104-96-221-146.deploy.static.akamaitechnologies.com
July 20, 2016

a104-96-221-83.deploy.static.akamaitechnologies.com
July 20, 2016

a104-96-220-154.deploy.static.akamaitechnologies.com
July 1, 2016

a104-96-220-146.deploy.static.akamaitechnologies.com
July 1, 2016

a23-3-13-186.deploy.static.akamaitechnologies.com
May 21, 2016

a104-96-220-128.deploy.static.akamaitechnologies.com
May 18, 2016

a104-96-220-129.deploy.static.akamaitechnologies.com
May 15, 2016

a104-96-220-184.deploy.static.akamaitechnologies.com
May 15, 2016

April 11, 2016

April 11, 2016

a23-62-6-208.deploy.static.akamaitechnologies.com
February 25, 2016

a184-28-17-169.deploy.static.akamaitechnologies.com
February 22, 2016

a184-28-17-200.deploy.static.akamaitechnologies.com
February 22, 2016

a23-220-148-49.deploy.static.akamaitechnologies.com
February 21, 2016

a23-220-148-65.deploy.static.akamaitechnologies.com
February 21, 2016

a23-0-160-96.deploy.static.akamaitechnologies.com
February 17, 2016

a23-0-160-97.deploy.static.akamaitechnologies.com
February 17, 2016

a184-25-157-73.deploy.static.akamaitechnologies.com
February 11, 2016

a184-25-157-75.deploy.static.akamaitechnologies.com
February 11, 2016

February 3, 2016

February 3, 2016

January 5, 2016

January 5, 2016

January 5, 2016

January 5, 2016

a23-62-63-144.deploy.static.akamaitechnologies.com
January 4, 2016

 
Showing 30 of 63 IP Addresses

File downloads found at URLs served by www5l.incredimail.com.

2 / 68      (PUP)

0 / 68
http://www5l.incredimail.com/im/setup/2009072001/default/.../IncrediMailSetup_fr.exe  (incredimail_incredimail_5.8.6_build_4332_francais_10318.exe)

15 / 68    (PUP)

5 / 68      (PUP)

1 / 68      (PUP)

4 / 68      (PUP)

 
Latest 30 of 206 download URLs

The following 420 files have been seen to comunicate with www5l.incredimail.com in live environments.

 
Latest 20 of 530 files

URL:
http://www5l.incredimail.com/

Web server:
nginx/0.7.62

Facebook:
Likes:  1
Shares:  1

Statistics are for the previous month.