The domain dl.exfilesdesk.com registered by Whois Privacy Shield Services was initially registered in November of 2014 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Cambridge, Massachusetts within the United States which resides on the Akamai Technologies, Inc. network.
Registrant:
Whois Privacy Shield Services
Registrar:
ISOROKU YAMAMOTO, LLC
Server location:
Massachusetts, United States (US)
Create date:
Friday, November 21, 2014
Expires date:
Saturday, November 21, 2015
Updated date:
Tuesday, November 25, 2014
ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US
Scanner detections:
Detections (96% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.FIRSERIASL.S, PUP.Installer.FIRSERIASL.G, PUP.Installer.FIRSERIASL.K, PUP.Installer.FIRSERIASL.M, PUP.Installer.FIRSERIASL.H, PUP.Installer.FIRSERIASL.Z, PUP.Installer.FIRSERIASL.E, PUP.Installer.FIRSERIASL.X, PUP.Installer.FIRSERIASL.J, PUP.OUTBROWSE.F, PUP.Installer.FIRSERIASL.F, PUP.Solimba.FIRSERIA.Bundler (M), PUP.Solimba.EilioDev.Installer (M), PUP.Solimba (M)
97.87%
Dr.Web
Trojan.DownLoader11.24441, Adware.Downware.2081
48.94%
Sophos
Solimba Installer, OutBrowse Revenyou, PUA 'Solimba Installer'
48.94%
G Data
Application.Bundler.Firseria, Win32.Application.Outbrowse
48.94%
IKARUS anti.virus
PUA.MSIL.Solimba, AdWare.BundleApp, PUA.OutBrowse
48.94%
VIPRE Antivirus
Threat.4782980, DownloadMR, Threat.4150696, Trojan.Win32.Generic, Threat.4784459, Threat.4758821
46.81%
Malwarebytes
PUP.Optional.Firseria, PUP.Optional.OutBrowse
46.81%
AVG
Generic, Adware BundleApp_r.AJ, Adware BundleApp.GS, Adware BundleApp_r.AV
46.81%
Agnitum Outpost
PUA.Solimba, Trojan.PWS.Agent, PUA.OutBrowse
46.81%
Comodo Security
Application.Win32.Firseria.MAP, Application.Win32.Firseria.AFGH
44.68%
Avira AntiVirus
APPL/Firseria.Gen8, Adware/Firseria.B
44.68%
Vba32 AntiVirus
Downware.Morstar
44.68%
Panda Antivirus
Adware/Firseria
44.68%
K7 AntiVirus
Unwanted-Program , Trojan
44.68%
NANO AntiVirus
Trojan.Win32.DownLoader11.ddphbo, Trojan.Win32.DownLoader11.ddvnyv, Trojan.Win32.DownLoader11.dehccv, Riskware.Win32.Fiseria.ddnzzd
44.68%
The domain dl.exfilesdesk.com has been seen to resolve to the following 13 IP addresses.
a184-51-126-74.deploy.static.akamaitechnologies.com
September 15, 2014
a23-32-241-72.deploy.static.akamaitechnologies.com
September 15, 2014
a23-32-241-88.deploy.static.akamaitechnologies.com
September 15, 2014
a184-51-126-9.deploy.static.akamaitechnologies.com
September 7, 2014
a184-51-126-33.deploy.static.akamaitechnologies.com
September 7, 2014
a23-62-7-43.deploy.static.akamaitechnologies.com
September 2, 2014
a23-62-7-25.deploy.static.akamaitechnologies.com
September 2, 2014
a23-62-6-81.deploy.static.akamaitechnologies.com
August 24, 2014
a23-62-6-64.deploy.static.akamaitechnologies.com
August 24, 2014
a23-0-160-9.deploy.static.akamaitechnologies.com
August 16, 2014
a23-0-160-48.deploy.static.akamaitechnologies.com
August 16, 2014
File downloads found at URLs served by dl.exfilesdesk.com.
Latest 30 of 49 download URLs
The following 42 files have been seen to comunicate with dl.exfilesdesk.com in live environments.
URL:
http://dl.exfilesdesk.com/
Google Analytics:
UA-48689684
Related Domains
30 of 618 related domains