download.freecompression.com
Domains By Proxy, LLC (Proxy Registrant)
Domain Information
The domain download.freecompression.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Tel Aviv, Tel Aviv within Israel which resides on the RIPE Network Coordination Centre network.
Registrant:
Domains By Proxy, LLC
Registrar:
GODADDY.COM, LLC
Server location:
Tel Aviv, Israel (IL)
Create date:
Monday, March 24, 2014
Expires date:
Friday, March 24, 2017
Updated date:
Friday, March 25, 2016
ASN:
AS6461 MFNX MFN - Metromedia Fiber Network
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Optional.Installer.R, PUP.Optional.Installer.T, PUP.Bandoo.Installer, PUP.Bandoo.BandooMedia.Installer (M), PUP.Bandoo.BandooMe.Installer (M), Threat.Win.Reputation.IMP, Win32.Generic, PUP.Bandoo (M)
100.00%
McAfee
SearchSuite, Program.SearchSuite
27.27%
K7 AntiVirus
Unwanted-Program , Trojan
27.27%
VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
27.27%
Malwarebytes
PUP.Optional.Bandoo
27.27%
Zillya! Antivirus
Adware.SearchSuite.Win64.20
22.73%
Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite, not-a-virus:WebToolbar.Win32.SearchSuite
22.73%
Dr.Web
Adware.Bandoo.13, Adware.Bandoo.194
22.73%
G Data
Win32.Adware.Bandoo, Win32.Application.Agent.VJFYZ5
22.73%
ESET NOD32
Win32/Toolbar.SearchSuite.J potentially unwanted application, Win32/Toolbar.SearchSuite.V potentially unwanted application
18.18%
Fortinet FortiGate
Riskware/SearchSuite
18.18%
Qihoo 360 Security
Win32/Virus.WebToolbar.49b, Win32/Virus.Adware.0ca
18.18%
Comodo Security
Application.Win32.Bandoo.D
18.18%
F-Prot
W32/A-d602c904, W32/SearchSuite.B
18.18%
The domain download.freecompression.com has been seen to resolve to the following 2 IP addresses.
94.31.0.25.IPYX-076665-ZYO.above.net
December 29, 2014
File downloads found at URLs served by download.freecompression.com.
The following 15 files have been seen to comunicate with download.freecompression.com in live environments.
URL:
http://download.freecompression.com/