download.cdn.expresdownload.com
Domains By Proxy, LLC (Proxy Registrant)
Domain Information
The domain download.cdn.expresdownload.com is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the nLayer Communications Internal/Backbone network.
Registrant:
Domains By Proxy, LLC
Registrar:
GODADDY.COM, LLC
Server location:
New York, United States (US)
Create date:
Wednesday, October 9, 2013
Expires date:
Monday, October 9, 2017
Updated date:
Wednesday, September 9, 2015
ASN:
AS4436 AS-GTT-4436 - nLayer Communications, Inc.,US
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Optional.Installer.BandooMedia.V, PUP.Optional.Installer.W, PUP.Bandoo.BandooMe.Installer (M)
100.00%
Malwarebytes
PUP.Optional.Bandoo
80.00%
ESET NOD32
Win32/iLivid (variant)
80.00%
Trend Micro House Call
TROJ_GEN.F47V0219, Suspicious_GEN.F47V0731
60.00%
Dr.Web
Adware.Bandoo.13
60.00%
VIPRE Antivirus
iLivid
60.00%
Baidu Antivirus
Adware.Win32.iLivid
60.00%
IKARUS anti.virus
PUA.SearchSuite
60.00%
Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite
40.00%
McAfee
Artemis!875998794E2E, Artemis!F461DB6FE8FE
40.00%
Comodo Security
Application.Win32.iLivid.~A
20.00%
Fortinet FortiGate
Riskware/ILivid
20.00%
XVirus List
Win.Detected
20.00%
avast!
Win32:Malware-gen
20.00%
The domain download.cdn.expresdownload.com has been seen to resolve to the following 20 IP addresses.
a104-96-221-83.deploy.static.akamaitechnologies.com
August 6, 2016
a104-96-221-91.deploy.static.akamaitechnologies.com
August 6, 2016
a23-67-250-113.deploy.static.akamaitechnologies.com
May 4, 2015
a23-67-250-104.deploy.static.akamaitechnologies.com
May 4, 2015
a96-6-113-56.deploy.akamaitechnologies.com
May 3, 2015
a96-6-113-128.deploy.akamaitechnologies.com
May 3, 2015
a184-29-106-34.deploy.static.akamaitechnologies.com
April 9, 2015
a184-29-106-72.deploy.static.akamaitechnologies.com
April 9, 2015
a23-62-7-11.deploy.static.akamaitechnologies.com
December 1, 2014
a23-62-7-32.deploy.static.akamaitechnologies.com
December 1, 2014
a23-62-6-65.deploy.static.akamaitechnologies.com
September 7, 2014
a23-62-6-88.deploy.static.akamaitechnologies.com
September 7, 2014
ip-69-31-29-231.nlayer.net
September 7, 2014
ip-69-31-29-236.nlayer.net
September 7, 2014
a184-51-126-57.deploy.static.akamaitechnologies.com
September 6, 2014
a184-51-126-66.deploy.static.akamaitechnologies.com
September 6, 2014
a23-0-160-33.deploy.static.akamaitechnologies.com
September 6, 2014
a23-0-160-49.deploy.static.akamaitechnologies.com
September 6, 2014
a23-67-242-73.deploy.static.akamaitechnologies.com
August 13, 2014
a23-67-242-35.deploy.static.akamaitechnologies.com
August 13, 2014
File downloads found at URLs served by download.cdn.expresdownload.com.
The following 137 files have been seen to comunicate with download.cdn.expresdownload.com in live environments.
URL:
http://download.cdn.expresdownload.com/