The domain download.expresdownload.com is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Tel Aviv, Tel Aviv within Israel which resides on the RIPE Network Coordination Centre network.
Registrant:
Domains By Proxy, LLC
Registrar:
GODADDY.COM, LLC
Server location:
Tel Aviv, Israel (IL)
Create date:
Wednesday, October 9, 2013
Expires date:
Monday, October 9, 2017
Updated date:
Wednesday, September 9, 2015
ASN:
AS6461 MFNX MFN - Metromedia Fiber Network
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Optional.Installer.BandooMedia.V, PUP.Optional.Installer.V, PUP.Optional.Installer.W, PUP.Optional.Installer.EE, PUP.Bandoo.BandooMedia.Installer (M), Win32.Generic, PUP.ILivid.WebBar (M), PUP.Bandoo (M)
96.55%
Malwarebytes
PUP.Optional.Bandoo
41.38%
VIPRE Antivirus
iLivid, Threat.5059975, Trojan.Win32.Generic
41.38%
ESET NOD32
Win32/iLivid (variant)
37.93%
Baidu Antivirus
Adware.Win32.iLivid, Adware.Win32.SearchSuite
37.93%
McAfee
Artemis!9556A78BB7AC, Artemis!C242B5A5B592, Artemis!B6A829DFA975, Artemis!875998794E2E, Artemis!430BA1894F53, Artemis!F461DB6FE8FE, Artemis!D0475DE2AB77, Artemis!7EFD1599C665, Artemis!7953344719D5, Artemis!919DBB95C7A3
34.48%
Dr.Web
Adware.Bandoo.13, Adware.Bandoo.19, Adware.Bandoo.168
27.59%
Fortinet FortiGate
Riskware/ILivid, Riskware/Win64_SearchSuite, Riskware/SearchSuite
24.14%
IKARUS anti.virus
PUA.Bandoo, PUA.SearchSuite, PUA.iLivid
24.14%
Avira AntiVirus
APPL/Downloader.Gen
24.14%
Trend Micro House Call
TROJ_GEN.F47V0219, Suspicious_GEN.F47V0617, Suspicious_GEN.F47V0717, Suspicious_GEN.F47V0723, Suspicious_GEN.F47V0731, Suspicious_GEN.F47V1028
20.69%
Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite
17.24%
Agnitum Outpost
PUA.Toolbar.SearchSuite
13.79%
Comodo Security
Application.Win32.iLivid.~A, UnclassifiedMalware
10.34%
The domain download.expresdownload.com has been seen to resolve to the following IP address.
94.31.0.27.IPYX-076665-ZYO.above.net
May 23, 2014
File downloads found at URLs served by download.expresdownload.com.
The following 9 files have been seen to comunicate with download.expresdownload.com in live environments.
URL:
http://download.expresdownload.com/
Google Analytics:
UA-30208384
Title:
“Torch Web Browser - Your All in One Internet Browser”
Description:
“Get more from the web with Torch Browser. Learn more about this unique browser here.”
Related Domains