dll512.loadarchive.biz

Fundacion Private Whois  (Proxy Registrant)

Domain Information

The domain dll512.loadarchive.biz is registered by proxy through INTERNET.BS CORP. and was originally registered in September of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Salt Lake City, Utah within the United States which resides on the Hosting Services, Inc. network.
Registrar:
INTERNET.BS CORP.

Server location:
Utah, United States (US)

Create date:
Monday, September 15, 2014

Expires date:
Monday, September 14, 2015

Updated date:
Monday, September 15, 2014

ASN:
AS29854 WESTHOST - WestHost, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ViaAdvertisingGroupLimited.k, PUP.Installer.ViaAdvertisingGroupLimited.T, PUP.Installer.ViaAdvertisingGroupLimited.CC, PUP.Installer.RighwayTechnologies.q, PUP.Installer.ViaAdvertisingGroupLimited.e, PUP.Installer.ViaAdvertisingGroupLimited.d, PUP.Installer.ViaAdvertisingGroupLimited.BB, PUP.Installer.ViaAdvertisingGroupLimited.i, PUP.Installer.ViaAdvertisingGroupLimited.m, PUP.Installer.Via Advertising, PUP.Via Advertising.Bundler, PUP.Via Advertising.ViaAdvertisingGroup.Bundler (M), PUP.Via Advertising.ViaAdver.Bundler (M), Threat.Win.Reputation.IMP, PUP.Via Advertising (M)
100.00%

VIPRE Antivirus
Threat.4758264, Threat.4925438
72.22%

avast!
Win32:Downloader-UEO [PUP], Win32:Adware-gen [Adw]
72.22%

Avira AntiVirus
APPL/Downloader.Gen8, TR/EDownload.J.2, PUA/EDownloader.Gen4
66.67%

Dr.Web
Adware.Downware.8424, Threat.Undefined, Adware.Downware.4798, Adware.Downware.8126, Adware.Downware.8583, Adware.Downware.8715
66.67%

herdProtect (fuzzy)
a variant of c05a86ddc32c5d228ca8ead9b70479b2951e5fad, a variant of 813ce05947e3f9ca9cf12282e2610985e4cf2649, a variant of a17107190d1f44aa7ee603da33bda6a6f6c80924
55.56%

ESET NOD32
Win32/ExpressDownloader.J potentially unwanted application
38.89%

AVG
Adware BundleApp_r, Righway Technologies, Generic, Adware Generic_r.AFD
27.78%

Malwarebytes
PUP.Optional.Downloader, PUP.Optional.YourFileDown
27.78%

Agnitum Outpost
Riskware.Agent
27.78%

ESET NOD32
Win32/ExpressDownloader (variant)
27.78%

K7 AntiVirus
Adware , Unwanted-Program
22.22%

Zillya! Antivirus
Downloader.Agent.Win32.221789, Downloader.Agent.Win32.222056, Trojan.Badur.Win32.22102
22.22%

IKARUS anti.virus
PUA.Expressdownloader
16.67%

MicroWorld eScan
Gen:Variant.Kazy.463192, Gen:Variant.Mikey.12297
16.67%

The domain dll512.loadarchive.biz has been seen to resolve to the following 2 IP addresses.

209.95.43.22.static.midphase.com
May 15, 2015

September 18, 2014

File downloads found at URLs served by dll512.loadarchive.biz.

7 / 68      (Adware)
http://dll512.loadarchive.biz/j5GWR3v4vFVy0b8UfIz/.../UzzNvkZ8WOxtqoy4OCpNg==  (spyhunter_v4.1.11.0_software_crack_downloader.exe)

URL:
http://dll512.loadarchive.biz/

Title:
“Welcome to YourFile Downloader!”

Web server:
nginx/1.2.1 (PHP/5.4.36-0+deb7u3)