Download
Community
knowledgeBase
» download.dwnload.org
Overview
Analysis
IPs Addresses (2)
Downloads (11)
Network (14)
Website Detail
download.dwnload.org
WhoisGuard, Inc. (Proxy Registrant)
Domain Information
The domain download.dwnload.org is registered by proxy through eNom, Inc.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Digital Ocean, Inc. network.
Registrant:
WhoisGuard, Inc.
Registrar:
eNom, Inc.
Server location:
New York, United States (US)
ASN:
AS393406 DIGITALOCEAN-ASN-NY3 - Digital Ocean, Inc.,US
Root domain:
dwnload.org
Whois:
2 dwnload.org records
Analysis
Scanner detections:
Detections (96% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Air Software.DRD Ventures.Bundler (M), PUP.Air Software.Download.Bundler (M), Threat.Win.Reputation.IMP, PUP.InstallCore.Securita.Installer (M), PUP.InstallCore.SafeInst.Installer (M), PUP.Air Software (M)
97.96%
avast!
Win32:Adware-CKF [PUP]
2.04%
IPs Addresses
The domain download.dwnload.org has been seen to resolve to the following 2 IP addresses.
159.203.107.180
fd-03-do-e-ny-3.gtdlrfwd.com
October 26, 2015
104.131.2.201
useast.gtdlrfwd.com
September 30, 2014
Downloads
File downloads found at URLs served by download.dwnload.org.
1 / 68 (Adware)
http://download.dwnload.org/v2/click/ftucuo66/?d=http://dwnload.org/.../java.exe&n=Java Runtime&key=10510ab6c337f21eee5c6c9d3c4ded1c1b0271575415e281a79604ad126a40c3&affiliate_image=&product_image=http://dwnload.org/.../java.png&sid=GUS2-java&filename=JavaSetup
(javasetup.exe)
1 / 68 (Adware)
http://download.dwnload.org/v2/click/ftucuo66/?d=http://dwnload.org/.../steam.exe&n=Steam&key=ca240dcbb76f726e8aaa3cef3bee00a8a6a3089c30748be882efff25006e745f&affiliate_image=&product_image=http://dwnload.org/.../steam.png&sid=GUS2-steam&filename=SteamSetup
(steamsetup.exe)
1 / 68 (Adware)
http://download.dwnload.org/v2/click/ftucuo66/?d=http://dwnload.org/.../internet-explorer.exe&n=Internet Explorer&key=609cfe4d58436358adcaf496de41942555d6e3c78dabda94509de0f8d4142e60&affiliate_image=&product_image=http://dwnload.org/.../internet-explorer.png&sid=GUS2-IE&filename=Internet_Explorer_Installer
(Internet_Explorer_Installer.exe)
1 / 68 (Adware)
http://download.dwnload.org/v2/click/ftucuo66/?d=http://dwnload.org/.../windowsmediaplayer.exe&n=Windows Media Player&key=d1f51a45e7a3cef7b62f4a27baa84a36bd0a5ca1b3c6a9f915d7ab5ada78faac&affiliate_image=&product_image=http://dwnload.org/.../windowsmediaplayer.png&sid=GUS2-windowsmediaplayer&filename=WindowsMediaPlayer
(36fcf3bd0114fe5da8c38e198e4871c3)
1 / 68 (Adware)
http://download.dwnload.org/v2/click/ftucuo66/?d=http://dwnload.org/.../word.exe&n=Microsoft Word 2010&key=c28b04f033c5a5dbf9985757b6997507a66032b256bf103255f819882306b4b9&affiliate_image=&product_image=http://dwnload.org/.../word.png&sid=GUS2-word&filename=MicrosoftWordSetup
(microsoftwordsetup.exe)
1 / 68 (Adware)
http://download.dwnload.org/v2/click/ftucuo66/?d=http://dwnload.org/.../word.exe&n=Microsoft Word&key=c28b04f033c5a5dbf9985757b6997507a66032b256bf103255f819882306b4b9&affiliate_image=&product_image=http://dwnload.org/.../word.png&sid=GUS2-word&filename=MicrosoftWord
(MicrosoftWord.exe)
1 / 68
(inconclusive)
http://download.dwnload.org/v2/click/e23c8396/?d=http://dwnload.org/.../java.exe&n=Java Runtime&key=10510ab6c337f21eee5c6c9d3c4ded1c1b0271575415e281a79604ad126a40c3&affiliate_image=&product_image=http://dwnload.org/.../java.png&sid=GUK2-java&filename=JavaSetup
(javasetup.exe)
1 / 68 (Adware)
http://download.dwnload.org/v2/click/ftucuo66/?d=http://dwnload.org/.../winrar.exe&n=Winrar&key=c75f31a534e48a120550ed5ef33ec605eb3da541734d976f971bbf88e3f72bad&affiliate_image=&product_image=http://dwnload.org/.../winrar.png&sid=GUS2-winrar&filename=Winrar_Installer
(Winrar_Installer.exe)
1 / 68 (Adware)
http://download.dwnload.org/v2/click/ftucuo66/?d=http://dwnload.org/.../dropbox.exe&n=DropBox&key=24ef96f98c9fcc0f1a34781e6000e61f4e7e7332ee4d024a1a0d2640db27aaf8&affiliate_image=&product_image=http://dwnload.org/.../dropbox.png&sid=GUS2-dropbox&filename=DropBoxSetup
(dropboxsetup.exe)
1 / 68 (Adware)
http://download.dwnload.org/v2/click/ftucuo66/?d=http://dwnload.org/.../itunes.exe&n=Apple iTunes&key=1cdf0e075f59f888cf6cd86081109953cfee027e9b5bc26b5f5373fd52c625bf&affiliate_image=&product_image=http://dwnload.org/.../itunes.png&sid=GUS2-itunes&filename=iTunesSetup
(iTunesSetup.exe)
1 / 68 (Adware)
http://download.dwnload.org/v2/click/ftucuo66/?d=http://dwnload.org/.../avast.exe&n=Avast Free Antivirus&key=f4434b89ed16e3a220b266f1cbac31281bddce3c26cbdb57ebd007c67dca97f1&affiliate_image=&product_image=http://dwnload.org/.../avast.png&sid=GUS2-avast&filename=AvastSetup
(avastsetup.exe)
Network Communications
The following 14 files have been seen to comunicate with download.dwnload.org in live environments.
TCP »
104.131.2.201
:80
setup.exe (Google Chrome by Download Assistant)
TCP »
104.131.2.201
:80
setup.exe (DVD Shrink by Download Publisher)
TCP »
104.131.2.201
:80
setup.exe (Java Runtime by Download Assistant)
TCP »
104.131.2.201
:80
setup.exe (WinZip by Download Assistant)
TCP »
104.131.2.201
:80
Microsoft_Security_Essentials_Setup.exe (Microsoft Security Essentials by Download Assistant)
TCP »
104.131.2.201
:80
Setup.exe (Java Runtime by Download Manager)
TCP »
104.131.2.201
:80
Avast_Setup_2015.exe (Avast by Download Assistant)
TCP »
104.131.2.201
:80
googlechromeupdatesetup.exe (Google Chrome by Install Helper)
TCP »
104.131.2.201
:80
setup_adobe_reader.exe (Adobe Reader by Install Helper)
TCP »
104.131.2.201
:80
AdobeReaderSetup-22796854.exe (Adobe Reader by Install Helper)
TCP »
104.131.2.201
:80
chrome_installer.exe (Google Chrome Browser by DownloadAsst_New)
TCP »
104.131.2.201
:80
microsoftsilverlightupdatesetup.exe (Microsoft Silverlight by Download Assistant)
TCP »
104.131.2.201
:80
Firefox Setup.exe (Firefox by Install Assistant)
TCP »
104.131.2.201
:80
malwarebytes anti-malware setup.exe (Malwarebytes Anti-Malware by Download Assistant)
Website Details
URL:
http://download.dwnload.org/
Title:
“Welcome to nginx!”
Web server:
nginx/1.4.6 (Ubuntu)
X