The domain dl1.afterdawn.com registered by AfterDawn Oy was initially registered in March of 1999 through CSL COMPUTER SERVICE LANGENBACH GMBH D/B/A JOKER.COM. This domain has been seen distributing various forms of adware (some being very aggressive) directly or via bundled installations. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network. The domain is associated with the publisher AfterDawn who is located in Oulu, Finland.
Registrar:
CSL COMPUTER SERVICE LANGENBACH GMBH D/B/A JOKER.COM
Server location:
Noord-Holland, Netherlands (NL)
Create date:
Wednesday, March 31, 1999
Expires date:
Sunday, March 31, 2019
Updated date:
Tuesday, February 11, 2014
ASN:
AS60781 LEASEWEB-NL LeaseWeb B.V.,NL
Scanner detections:
Adware distribution
Scan engine
Details
Detections
Rising Antivirus
PE:PUF.OpenCandy!1.9DE5, PE:Trojan.Win32.SpeedingUpMyPC.a!1075357520, PE:Malware.RDM.39!5.2D[F1]
38.46%
Reason Heuristics
PUP.iMesh.Installer.Installer.Meta (L), PUP.DigitalWave.Bundler (L), PUP.DigitalWave.Bundler.Installer.Meta (L), (M), Win32.Generic
38.46%
ESET NOD32
Win32/OpenCandy, Win32/OpenCandy.C potentially unsafe (variant), Win32/OpenCandy.A potentially unsafe (variant)
30.77%
Dr.Web
Adware.OpenCandy.3, Adware.Toolbar.576, Adware.Toolbar.665
23.08%
G Data
Trojan.GenericKD.1630386, Win32.Application.Dealply, Win32.Application.OpenCandy
23.08%
Bkav FE
W32.Clodabf.Trojan, W32.Clod26e.Trojan
15.38%
Malwarebytes
PUP.Optional.OpenCandy
15.38%
Trend Micro House Call
ADW_OPENCANDY, Suspicious_GEN.F47V0506
15.38%
XVirus List
Win.Detected
15.38%
Fortinet FortiGate
Riskware/OpenCandy
15.38%
Agnitum Outpost
Adware.OpenCandy
7.69%
Trend Micro
ADW_OPENCANDY
7.69%
Vba32 AntiVirus
AdWare.OpenCandy
7.69%
AhnLab V3 Security
ASD.Prevention
7.69%
Quick Heal
(Suspicious) - DNAScan
7.69%
The domain dl1.afterdawn.com has been seen to resolve to the following IP address.
imuri01.afterdawn.net
May 5, 2015
File downloads found at URLs served by dl1.afterdawn.com.
11 / 68 (false positives)
Latest 30 of 255 download URLs
The following 6 files have been seen to comunicate with dl1.afterdawn.com in live environments.
URL:
http://dl1.afterdawn.com/
Google Analytics:
UA-2099875
Title:
“AfterDawn: Software downloads”
Description:
“Large selection of reviewed shareware and freeware software.”
Related Domains