desyncs.com

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain desyncs.com is registered by proxy through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM and was originally registered in February of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scranton, Pennsylvania within the United States which resides on the Network Operations Center Inc. network.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Pennsylvania, United States (US)

Create date:
Wednesday, February 13, 2013

Expires date:
Friday, February 13, 2015

Updated date:
Monday, February 10, 2014

ASN:
AS21788 NOC - Network Operations Center Inc.

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.ExpressFiles.A
100.00%

K7 AntiVirus
Unwanted-Program
100.00%

avast!
Win32:Downloader-TSH [PUP]
100.00%

Sophos
Express Files
100.00%

VIPRE Antivirus
ExpressFiles Installer, Threat.4783941
100.00%

AhnLab V3 Security
PUP/Win32.ExpressFiles
100.00%

AVG
MalSign.Faglaro Enterprises Limited
100.00%

Reason Heuristics
PUP.FaglaroEnterprisesLimited.R, PUP.FaglaroEnterprisesLimited.V
100.00%

G Data
Win32.Application.ExpressFiles
100.00%

Bkav FE
W32.Clod58d.Trojan, W32.Clodb45.Trojan
66.67%

McAfee
Artemis!062BDA96A95E, Artemis!B773A2DA41C5
66.67%

Trend Micro House Call
TROJ_GEN.F47V1118, TROJ_GEN.F47V1122
66.67%

ESET NOD32
Win32/ExpressFiles (variant)
66.67%

herdProtect (fuzzy)
a variant of 2b80df6571c45c48ae793fb3a8aca31af677b1e8
66.67%

Avira AntiVirus
Adware/ExpressFiles.G
33.33%

The domain desyncs.com has been seen to resolve to the following 3 IP addresses.

October 20, 2014

184-82-101-115.static.hostnoc.net
March 14, 2014

184-82-62-107.static.hostnoc.net
February 6, 2014

File downloads found at URLs served by desyncs.com.

URL:
http://desyncs.com/

Web server:
nginx (PHP/5.2.17)