The domain dl.downownfiles.com registered by Corp New Ventures Services was initially registered in October of 2015 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Toronto, Ontario within Canada which resides on the Akamai Technologies, Inc. network.
Registrant:
Corp New Ventures Services
Registrar:
EUNAMEFLOOD.COM LLC
Server location:
Ontario, Canada (CA)
Create date:
Thursday, October 22, 2015
Expires date:
Saturday, October 22, 2016
Updated date:
Thursday, October 29, 2015
ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US
Scanner detections:
Detections (96% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.EilioDevelopmentssl.J, PUP.Installer.EilioDevelopmentssl.O, PUP.Installer.EilioDevelopmentssl.a, PUP.Installer.Solimba, PUP.EilioDevelopments, PUP.Solimba.EilioDevelopmentssl.Installer (M), PUP.Solimba.EilioDev.Installer (M), PUP.Solimba.EilioDev.Bundler (M), PUP.Solimba (M)
96.30%
VIPRE Antivirus
Threat.4758821, DownloadMR, Threat.4782980
22.22%
MicroWorld eScan
Gen:Variant.Application.Bundler.Kazy.132995, Gen:Variant.Adware.Kazy.559386
22.22%
Kaspersky
not-a-virus:Downloader.Win32.Morstar
22.22%
Bitdefender
Gen:Variant.Application.Bundler.Kazy.132995, Gen:Variant.Adware.Kazy.559386
22.22%
Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Kazy.132995, Application.Bundler.Firseria.U, Gen:Variant.Adware.Kazy.559386
18.52%
ESET NOD32
MSIL/Solimba.AH potentially unwanted application
18.52%
Comodo Security
Application.Win32.Solimba.LSW, Application.Win32.Firseria.MAP
18.52%
Avira AntiVirus
APPL/Firseria.Gen8
18.52%
G Data
Gen:Variant.Application.Bundler.Kazy.132995, Gen:Variant.Adware.Kazy.559386
18.52%
Vba32 AntiVirus
Downware.Morstar
18.52%
AVG
Adware BundleApp_r.AV, Generic, Adware BundleApp.GY, Adware BundleApp.IA
18.52%
AhnLab V3 Security
PUP/Win32.Firseria, PUP/Win32.Bundler
18.52%
Malwarebytes
PUP.Optional.Solimba, PUP.Optional.Firseria
18.52%
K7 AntiVirus
Unwanted-Program
18.52%
The domain dl.downownfiles.com has been seen to resolve to the following 9 IP addresses.
a72-246-43-10.deploy.akamaitechnologies.com
May 7, 2015
a72-246-43-56.deploy.akamaitechnologies.com
May 7, 2015
a184-51-126-98.deploy.static.akamaitechnologies.com
January 13, 2015
a184-51-126-82.deploy.static.akamaitechnologies.com
January 13, 2015
a23-62-7-168.deploy.static.akamaitechnologies.com
November 30, 2014
a23-62-7-155.deploy.static.akamaitechnologies.com
November 30, 2014
a184-29-106-123.deploy.static.akamaitechnologies.com
September 30, 2014
a184-29-106-138.deploy.static.akamaitechnologies.com
September 30, 2014
File downloads found at URLs served by dl.downownfiles.com.
The following 212 files have been seen to comunicate with dl.downownfiles.com in live environments.
URL:
http://dl.downownfiles.com/