downloadflash.net

Kilian Janssen

Domain Information

The domain downloadflash.net registered by Kilian Janssen was initially registered in January of 2016 through KEY-SYSTEMS GMBH. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Tilburg, Noord-Brabant within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
KEY-SYSTEMS GMBH

Server location:
Noord-Brabant, Netherlands (NL)

Create date:
Thursday, January 14, 2016

Expires date:
Saturday, January 14, 2017

Updated date:
Thursday, January 14, 2016

ASN:
AS50673 SERVERIUS-AS Serverius Holding B.V.,NL

Scanner detections:
Detections  (67% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Air Software.Installe.Installer (M), PUP.InstallCore.AC.Installer (M)
100.00%

Dr.Web
Adware.Downware.13038
50.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
50.00%

The domain downloadflash.net has been seen to resolve to the following 2 IP addresses.

premium07.totaalholding.nl
June 23, 2016

www58.totaalholding.nl
April 21, 2016

File downloads found at URLs served by downloadflash.net.

1 / 68      (Adware)
http://downloadflash.net/installer.php  (adobe_flash_player-2d26d3ee57031bb5.exe)

3 / 68      (Adware)
http://downloadflash.net/installer.php  (kik for computer setup-efb5180a561c2ec1.exe)

0 / 68
http://downloadflash.net/.../adobe_flash_player.exe  (flashplayer18ax_ga_install.exe)

The following 2 files have been seen to comunicate with downloadflash.net in live environments.

URL:
http://downloadflash.net/

Google Analytics:
UA-64694985

Title:
“Adobe Flash Player - Free download”

Description:
“Download Adobe Flash Player free online.”

Web server:
Apache/2.4.18 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4 (PHP/5.6.21)