downland.aboede.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain downland.aboede.com is registered by proxy through ENOM, INC. and was originally registered in February of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Wednesday, February 26, 2014

Expires date:
Thursday, February 26, 2015

Updated date:
Wednesday, February 26, 2014

ASN:
AS16265 FIBERRING LeaseWeb B.V.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.PaymentsInteractiveSL.L, PUP.Solimba.EilioDevelopmentssl.Installer (M), PUP.Tuguu.PaymentsInteractive.Bundler (M), PUP.installCore.STMSetup.Installer (M), PUP.Tuguu.Bundler, PUP.Tuguu.Payments.Bundler (M), PUP.Tuguu.Cloverme.Bundler (M), PUP.Tuguu (M)
100.00%

Malwarebytes
PUP.Optional.DomalQ, .PUP.Optional.Solimba
15.38%

Agnitum Outpost
PUA.DomaIQ, PUA.Downloader
15.38%

avast!
Win32:PUP-gen [PUP], Win32:Solimba-M [PUP]
15.38%

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ, not-a-virus:Downloader.Win32.Morstar
15.38%

Sophos
Troj/MSIL-MD, PUA.Solimba Installer
15.38%

Dr.Web
Trojan.DownLoader9.33391, Trojan.DownLoader11.24441
15.38%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4782980
15.38%

Avira AntiVirus
APPL/DomaIQ.Gen, APPL/Firseria.Gen8
15.38%

G Data
Win32.Application.DomalQ, Gen:Variant.Application.Bundler.Kazy.132995
15.38%

Vba32 AntiVirus
BScope.Downware.DomaIQ, Downware.Morstar
15.38%

IKARUS anti.virus
Virus.Win32.Dropper, PUA.MSIL.Solimba
15.38%

AVG
DomaIQ.R, Adware BundleApp_r
15.38%

Panda Antivirus
PUP/MultiToolbar.A, Trj/Genetic.gen
15.38%

McAfee
RDN/Generic.bfr!et
7.69%

The domain downland.aboede.com has been seen to resolve to the following IP address.

March 27, 2014

File downloads found at URLs served by downland.aboede.com.

1 / 68      (Adware)
http://downland.aboede.com/.../flashplayer.exe  (84f921212052726d3a55ebdab55b8b4d)

1 / 68      (Adware)
http://downland.aboede.com/.../flashplayer.exe  (4229bbfeb6b5e6faa463b7444b272453)

1 / 68      (Adware)
http://downland.aboede.com/.../flashplayer.exe  (22180206e15df85bc9a71c0209c77e82)

1 / 68      (Adware)
http://downland.aboede.com/.../flashplayer.exe  (9b46dbbb231ece5f6af6762b303f5996)

1 / 68      (Adware)
http://downland.aboede.com/.../flashplayer.exe  (609d03e7ef8d81c90c2e78773111463a)

1 / 68      (Adware)
http://downland.aboede.com/.../flashplayer.exe  (36faa3ef223dbea8ddf4023ae8ab32ce)

1 / 68      (Adware)
http://downland.aboede.com/.../flashplayer.exe  (857949984142c6c4cbe3836d08a98489)

1 / 68      (Adware)
http://downland.aboede.com/.../flashplayer.exe  (42125d937168d9244247414c1efb99a9)

1 / 68      (Adware)
http://downland.aboede.com/.../flashplayer.exe  (3eb70e52871776231d4417b417b515e3)

1 / 68      (Adware)
http://downland.aboede.com/.../flashplayer.exe  (7637082778f084fea1c90a2753f56c25)

1 / 68      (Adware)
http://downland.aboede.com/.../flashplayer.exe  (75b85eb96fcc250584ae2af5c5d88ee0)

29 / 68    (Adware)
http://downland.aboede.com/.../flashplayer.exe  (2958ab68ff2da8229367c21795e8be76)

16 / 68    (Adware)
http://downland.aboede.com/.../flashplayer.exe  (977812100e857617d42bbb019c0b3277)

URL:
http://downland.aboede.com/

Title:
“LNMP一键安装包 by Licess”

Description:
“您已成功安装LNMP一键安装包!”

Web server:
nginx

Facebook:
Shares:  1

Alexa:
Global rank:  241,760
Backlinks:  3

Statistics are for the previous month (Alexa statistics are for entire aboede.com).