dl.downownfiles.com

Corp New Ventures Services

Domain Information

The domain dl.downownfiles.com registered by Corp New Ventures Services was initially registered in October of 2015 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Toronto, Ontario within Canada which resides on the Akamai Technologies, Inc. network.
Registrar:
EUNAMEFLOOD.COM LLC

Server location:
Ontario, Canada (CA)

Create date:
Thursday, October 22, 2015

Expires date:
Saturday, October 22, 2016

Updated date:
Thursday, October 29, 2015

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US

Root domain:

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.EilioDevelopmentssl.J, PUP.Installer.EilioDevelopmentssl.O, PUP.Installer.EilioDevelopmentssl.a, PUP.Installer.Solimba, PUP.EilioDevelopments, PUP.Solimba.EilioDevelopmentssl.Installer (M), PUP.Solimba.EilioDev.Installer (M), PUP.Solimba.EilioDev.Bundler (M), PUP.Solimba (M)
96.30%

VIPRE Antivirus
Threat.4758821, DownloadMR, Threat.4782980
22.22%

MicroWorld eScan
Gen:Variant.Application.Bundler.Kazy.132995, Gen:Variant.Adware.Kazy.559386
22.22%

Kaspersky
not-a-virus:Downloader.Win32.Morstar
22.22%

Bitdefender
Gen:Variant.Application.Bundler.Kazy.132995, Gen:Variant.Adware.Kazy.559386
22.22%

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Kazy.132995, Application.Bundler.Firseria.U, Gen:Variant.Adware.Kazy.559386
18.52%

ESET NOD32
MSIL/Solimba.AH potentially unwanted application
18.52%

Comodo Security
Application.Win32.Solimba.LSW, Application.Win32.Firseria.MAP
18.52%

Avira AntiVirus
APPL/Firseria.Gen8
18.52%

G Data
Gen:Variant.Application.Bundler.Kazy.132995, Gen:Variant.Adware.Kazy.559386
18.52%

Vba32 AntiVirus
Downware.Morstar
18.52%

AVG
Adware BundleApp_r.AV, Generic, Adware BundleApp.GY, Adware BundleApp.IA
18.52%

AhnLab V3 Security
PUP/Win32.Firseria, PUP/Win32.Bundler
18.52%

Malwarebytes
PUP.Optional.Solimba, PUP.Optional.Firseria
18.52%

K7 AntiVirus
Unwanted-Program
18.52%

The domain dl.downownfiles.com has been seen to resolve to the following 9 IP addresses.

March 2, 2016

a72-246-43-10.deploy.akamaitechnologies.com
May 7, 2015

a72-246-43-56.deploy.akamaitechnologies.com
May 7, 2015

a184-51-126-98.deploy.static.akamaitechnologies.com
January 13, 2015

a184-51-126-82.deploy.static.akamaitechnologies.com
January 13, 2015

a23-62-7-168.deploy.static.akamaitechnologies.com
November 30, 2014

a23-62-7-155.deploy.static.akamaitechnologies.com
November 30, 2014

a184-29-106-123.deploy.static.akamaitechnologies.com
September 30, 2014

a184-29-106-138.deploy.static.akamaitechnologies.com
September 30, 2014

File downloads found at URLs served by dl.downownfiles.com.

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../WiFi Auditor.exe  (4ce0e2d2655fdcf694e790c0ae618fd0)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../Show Box Installer.exe  (32eb77367872423da3d0df25521c72cd)

1 / 68      (Adware)
http://dl.downownfiles.com/n/3.1.27/.../Whatsapp.exe  (820161fce0479d8c5fb47036463480b0)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../Facebook for Windows.exe  (72662a5bdebb87b7a280aa233ffa219c)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../cars juego.exe  (9c750f3392b96c62c8c47834f144c043)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../Madagascar 2.exe  (e30957e8dfa5db6dfa21b669694436dd)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../FLV_Media_Player.exe  (066d0d017ac07a7ad048b06a9fd1dc2a)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../Apophysis.exe  (fab9762f1aee98b3191fda666ad16ce5)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../Bluestacks.exe  (d4fd55497cacdb37637f579669f17d14)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../Whatsapp.exe  (bbc2abdf88ac9c7c3f146588c0b6d19b)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../serious sam.exe  (8f9def2327e8076476b5f03f59177c2c)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../Wechat.exe  (7e7888d06a12ff1e09f3224b7b7e1b66)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../Counter Strike.exe  (c1ca243e1b11970679843c8cc8aec122)

1 / 68
http://dl.downownfiles.com/n/.../Minecraft.exe  (b63ccb43f2779cbea5d8d3ce2e3d90fb)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../KIK Messenger.exe  (e5ab372df785b9719f7b834454f3c3db)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../Nero.exe  (ca3f9e4b1ad0806e96c7c28701ae2b36)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../Showbox Installer.exe  (8b7c8e3c7145a5ca7e77c2ce7f5f852e)

1 / 68      (Adware)
http://dl.downownfiles.com/n/.../Thor The Dark World.exe  (206466b83b8bdc99792ad66a27f65e19)

1 / 68      (Adware)

1 / 68      (Adware)

12 / 68    (Adware)
http://dl.downownfiles.com/n/.../Show Box.exe  (dc8f744b1c34ddc931a9cebc71121869)

32 / 68    (Adware)

33 / 68    (Adware)

34 / 68    (Adware)

31 / 68    (Adware)
http://dl.downownfiles.com/n/.../File_installer.exe  (9147063fc3dd13c1289225c250c68a82)

16 / 68    (Adware)
http://dl.downownfiles.com/n/3.1.24.5.2/.../JW Player.exe  (3ecda7b457cdb71e308babedcca3d603)

The following 212 files have been seen to comunicate with dl.downownfiles.com in live environments.

 
Latest 20 of 220 files

URL:
http://dl.downownfiles.com/

Web server:
Apache