download.faceoffmax.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download.faceoffmax.com is registered by proxy through GODADDY.COM, LLC and was originally registered in July of 2009. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the Linode network.
Registrar:
GODADDY.COM, LLC

Server location:
Texas, United States (US)

Create date:
Monday, July 13, 2009

Expires date:
Wednesday, July 13, 2016

Updated date:
Wednesday, April 22, 2015

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Root domain:

Scanner detections:
Detections  (88% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.TenkiTechnologyCo.BB, PUP.Optional.Installer, (M), PUP.CoolwareMax.FaceOffMax (M)
87.50%

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant), Win32/Bundled.Toolbar.Ask.G potentially unsafe (variant)
50.00%

K7 AntiVirus
Unwanted-Program
25.00%

Dr.Web
Program.Unwanted.485
12.50%

IKARUS anti.virus
PUA.Offer
12.50%

Malwarebytes
PUP.Optional.APNToolBar
12.50%

The domain download.faceoffmax.com has been seen to resolve to the following IP address.

li46-252.members.linode.com
May 1, 2014

File downloads found at URLs served by download.faceoffmax.com.

3 / 68      (inconclusive)
http://download.faceoffmax.com/.../FaceOffMaxSetup.exe  (face.off.max.3.7.5.6_soft98.ir.exe)

1 / 68      (PUP)

1 / 68      (Malware)

4 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (Malware)

3 / 68      (PUP)
http://download.faceoffmax.com/.../FaceOffMaxSetup.exe  (18786f74ca5658a3b2ca9bc86fcbd0ee)

2 / 68      (PUP)
http://download.faceoffmax.com/.../FaceOffMaxSetup.exe  (face-off-max-3-6-0-2-en-win.exe)

The following 2 files have been seen to comunicate with download.faceoffmax.com in live environments.

URL:
http://download.faceoffmax.com/

Title:
“Kloxo Control Panel”

Web server:
Apache/2.2.21 (CentOS) (PHP/5.2.6)