The domain download.garenatotal.com is registered by proxy through NAME.COM, INC. and was originally registered in January of 2013. Currently this domain has been known to host various forms of malware. The hosted servers are located in San Francisco, California within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrant:
Whois Privacy Protection Service, Inc.
Server location:
California, United States (US)
Create date:
Tuesday, January 29, 2013
Expires date:
Sunday, January 29, 2017
Updated date:
Friday, January 22, 2016
ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US
Scanner detections:
Malware distribution (64% detected)
Scan engine
Details
Detections
F-Prot
W32/NewMalware-LSU-based!Maximu, W32/Sality.gen2, W32/VB.AD.gen, W32/Sality.E.gen, W32/SuspPack.AA.gen
78.95%
avast!
Win32:Malware-gen, Win32:Sality, Win32:SaliCode, Win32:Kukacka, Win32:VB-OJQ [Wrm], Win32:Crypt-SJB [Trj]
78.95%
Norman
Suspicious_Gen4.GYYJW, Win32.Sality.3, Trojan.Generic.6753864, Trojan.Generic.8613015, Win32.Jeefo.B
73.68%
ESET NOD32
Win32/Sality.NBA virus, Win32/VB.OSK trojan, Win32/VB.QQC trojan
68.42%
Microsoft Security Essentials
Threat.Undefined
68.42%
Emsisoft Anti-Malware
Dropped:Trojan.Generic.11647061, Win32.Sality, Trojan.Generic.6753864, Trojan.Generic.8613015, Win32.Jeefo
63.16%
Dr.Web
Win32.Sector.30, Trojan.Siggen6.54687, Trojan.Siggen6.29778
57.89%
McAfee
Artemis!F50A4D077EE6, Virus.W32/Sality.gen.z, Virus.W32/Swisyn.ag
52.63%
Kaspersky
Trojan.Win32.Swisyn, Virus.Win32.Sality, Trojan-Dropper.Win32.VB
47.37%
VIPRE Antivirus
Trojan.Win32.Generic, Threat.4758034, Threat.4721115, Threat.4763461
36.84%
AVG
Generic11_c, Win32/Sality, Win32/Hidrag.A
36.84%
Qihoo 360 Security
Win32/RootKit.Rootkit.7e5, HEUR/QVM06.2.Malware.Gen
10.53%
Reason Heuristics
Threat.Win.Reputation.IMP
10.53%
Sophos
Mal/ZipMal-A, Virus 'Mal/Sality-D'
10.53%
F-Secure
Trojan.Generic.6753864, Win32.Sality.3
10.53%
The domain download.garenatotal.com has been seen to resolve to the following 6 IP addresses.
cf-173-245-61-6.cloudflare.com
June 9, 2014
cf-173-245-60-6.cloudflare.com
June 9, 2014
File downloads found at URLs served by download.garenatotal.com.
URL:
http://download.garenatotal.com/
SSL certificate subject:
CN=sni37355.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated
SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB
Web server:
cloudflare-nginx