zone4.izabelcoin.com

PERFECT PRIVACY, LLC  (Proxy Registrant)

Domain Information

The domain zone4.izabelcoin.com is registered by proxy through Network Solutions, LLC and was originally registered in July of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Manassas, Virginia within the United States which resides on the Leaseweb USA, Inc. network.
Registrar:
Network Solutions, LLC

Server location:
Virginia, United States (US)

Create date:
Wednesday, July 1, 2015

Expires date:
Friday, July 1, 2016

Updated date:
Wednesday, July 1, 2015

ASN:
AS30633 LEASEWEB-US - Leaseweb USA, Inc.,US

Root domain:

Scanner detections:
Detections  (73% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/BitCoinMiner.BY potentially unsafe application, Win32/Sality.NBA virus
81.82%

Dr.Web
Trojan.BtcMine.893, infected with Trojan.BtcMine.907, Win32.Sector.30
54.55%

Kaspersky
not-a-virus:HEUR:RiskTool.Win32.BitCoinMiner, Virus.Win32.Sality
54.55%

Emsisoft Anti-Malware
Gen:Variant.Application.BitcoinMiner.16, Win32.Sality, Zum.BitCoinMiner
45.45%

VIPRE Antivirus
Threat.4150696, Threat.4721115, Threat.4741001
45.45%

AVG
Adware Generic_r.AVO, Win32/Sality
36.36%

avast!
Win32:Evo-gen [Susp], Win32:SaliCode
36.36%

Reason Heuristics
PUP.Amonitize.OpenSource.Installer (M), Adware.Amonetize.OpenSource.Installer.Meta (M)
27.27%

Norman
Gen:Variant.Application.BitcoinMiner.16, Win32.Sality.3
27.27%

Sophos
PUA 'CpuMiner', PUA 'Bitcoin Miner'
27.27%

McAfee
Program.Artemis!FC01AC55A333, Virus.Artemis!F74B3B353D90
27.27%

Microsoft Security Essentials
Threat.Undefined
18.18%

F-Prot
W32/Sality.gen2
18.18%

F-Secure
Win32.Sality.3
9.09%

The domain zone4.izabelcoin.com has been seen to resolve to the following 2 IP addresses.

March 2, 2016

hosted-by.Eqserver.com
March 2, 2016

File downloads found at URLs served by zone4.izabelcoin.com.

0 / 68
https://zone4.izabelcoin.com/Zone4.exe  (b1738091fdfe8f55ebb09d5898731fdf)

0 / 68
https://zone4.izabelcoin.com/Zone4.exe  (e9c17d1d182a0cb22ba3f08483bdef06)

7 / 68      (Infected)
https://zone4.izabelcoin.com/Zone4.exe  (77f6f1525adb89b4cd5b4a8a1cdd27a0)

0 / 68
https://zone4.izabelcoin.com/Zone4.exe  (93b53741739a1878c416743bf0f8d7d6)

10 / 68    (PUP)
https://zone4.izabelcoin.com/Zone4.exe  (00a50a6c3747e0b4fdf05000fc608416)

1 / 68      (PUP)
https://zone4.izabelcoin.com/Zone4.exe  (38f0cbcf28810d1c2e26733b998e6973)

11 / 68    (PUP)
https://zone4.izabelcoin.com/Zone4.exe  (634c5b4426d8a1711e5a3f567bce9a91)

4 / 68      (Malware)

4 / 68      (Malware)
https://zone4.izabelcoin.com/Zone4.exe  (a23dfa8505163d2e1e2bffcd62d2b0b2)

4 / 68      (Malware)

0 / 68
https://zone4.izabelcoin.com/Zone4.exe  (1ba658032eb4d038fd14d67ac9906b98)

7 / 68      (PUP)
https://zone4.izabelcoin.com/Zone4.exe  (07c380edc1dcd8d40a0711808929fe46)

3 / 68      (Adware)

4 / 68      (PUP)
https://zone4.izabelcoin.com/Zone4.exe  (fc01ac55a333eecd8b2624c5a8f654df)

1 / 68      (Adware)

The following 7 files have been seen to comunicate with zone4.izabelcoin.com in live environments.

URL:
http://zone4.izabelcoin.com/

SSL certificate subject:
CN=zone4.izabelcoin.com

SSL certificate issuer:
CN=Let's Encrypt Authority X1, O=Let's Encrypt, C=US

Web server:
keycdn-engine