dl.d0wnpzivrubajjui.net

United Privacy Corp

Domain Information

The domain dl.d0wnpzivrubajjui.net registered by United Privacy Corp was initially registered in November of 2014 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Fort Myers, Florida within the United States which resides on the Akamai Technologies, Inc. network.
Registrar:
GREENZONEDOMAINS INC.

Server location:
Florida, United States (US)

Create date:
Friday, November 21, 2014

Expires date:
Saturday, November 21, 2015

Updated date:
Friday, November 21, 2014

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.FIRSERIASL.P, PUP.Installer.FIRSERIASL.N, PUP.Installer.FIRSERIASL.CC, PUP.Installer.FIRSERIASL.X, PUP.Installer.FIRSERIASL.K, PUP.Installer.FIRSERIASL.R, PUP.Installer.FIRSERIASL.Q, PUP.Installer.FIRSERIASL.V, PUP.Solimba.FIRSERIA.Bundler (M), PUP.Solimba (M)
100.00%

Avira AntiVirus
APPL/Firseria.Gen8
50.00%

Emsisoft Anti-Malware
Application.Bundler.Firseria.M
40.00%

IKARUS anti.virus
AdWare.BundleApp, PUA.MSIL.Solimba
40.00%

AVG
Generic, Adware BundleApp.GT, BundleApp_r, Adware BundleApp.GS
40.00%

Panda Antivirus
Adware/Firseria
40.00%

Dr.Web
Trojan.DownLoader11.24441
36.67%

Kaspersky
not-a-virus:Downloader.Win32.Morstar
36.67%

VIPRE Antivirus
Threat.4782980, Trojan.Win32.Generic, DownloadMR
36.67%

Bitdefender
Application.Bundler.Firseria.M
36.67%

Sophos
Solimba Installer, PUA 'Solimba Installer'
36.67%

F-Prot
W32/A-a2151e6a, W32/A-eac696bb
36.67%

Baidu Antivirus
Adware.Win32.FirseriaInstaller, Adware.MSIL.Solimba
36.67%

Qihoo 360 Security
Win32/Trojan.Adware.37e
36.67%

avast!
Win32:PUP-gen [PUP]
36.67%

The domain dl.d0wnpzivrubajjui.net has been seen to resolve to the following 6 IP addresses.

January 22, 2015

a23-0-160-41.deploy.static.akamaitechnologies.com
September 7, 2014

a23-0-160-49.deploy.static.akamaitechnologies.com
September 7, 2014

a23-0-160-73.deploy.static.akamaitechnologies.com
September 7, 2014

a23-62-6-91.deploy.static.akamaitechnologies.com
September 2, 2014

a23-62-6-42.deploy.static.akamaitechnologies.com
September 2, 2014

File downloads found at URLs served by dl.d0wnpzivrubajjui.net.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.d0wnpzivrubajjui.net/n/3.1.22.13/.../WinRAR.exe  (f9c062d7b0d2237507a28ff075ac9822)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.d0wnpzivrubajjui.net/n/3.1.22.13/.../Skype.exe  (1e81a169f3d5c816a69d2ab14c524b93)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

35 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.d0wnpzivrubajjui.net/n/3.1.22.13/.../WinRAR.exe  (0d2de9d948a2406f6b311936933a3e3d)

1 / 68      (Adware)
http://dl.d0wnpzivrubajjui.net/n/3.1.22.13/.../Encore.exe  (4f0361d02779aa608c0710953e12bea7)

1 / 68      (Adware)

37 / 68    (Adware)

35 / 68    (Adware)

49 / 68    (Adware)

33 / 68    (Adware)

31 / 68    (Adware)

31 / 68    (Adware)

32 / 68    (Adware)

49 / 68    (Adware)

23 / 68    (Adware)

 
Latest 30 of 30 download URLs

The following 78 files have been seen to comunicate with dl.d0wnpzivrubajjui.net in live environments.

 
Latest 20 of 79 files

URL:
http://dl.d0wnpzivrubajjui.net/

Google Analytics:
UA-48689684

Title:
“d0wnpzivrubajjui.net”

Web server:
nginx

30 of 618 related domains