downprov.gas-split.com

Corp New Ventures Services

Domain Information

The domain downprov.gas-split.com registered by Corp New Ventures Services was initially registered in October of 2015 through DOMAINCONTEXT, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Singapore, Singapore within Singapore which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
MAGNOLIA DOMAINS, LLC

Server location:
Singapore, Singapore (SG)

Create date:
Monday, October 19, 2015

Expires date:
Wednesday, October 19, 2016

Updated date:
Monday, October 26, 2015

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Root domain:

Scanner detections:
Detections  (69% detected)

Scan engine
Details
Detections

VIPRE Antivirus
Threat.4657539, Trojan.Win32.Generic.pak!cobra
93.75%

Clam AntiVirus
Win.Adware.Amonetize-511, Win.Adware.Amonetize-703
87.50%

Comodo Security
Application.Win32.LoadMoney.IARS
75.00%

Trend Micro House Call
Suspicious_GEN.F47V0120, Suspicious_GEN.F47V0128, TROJ_GEN.R047H09B315, Suspicious_GEN.F47V0127, Suspicious_GEN.F47V0129, Suspicious_GEN.F47V0209
65.63%

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen, HEUR/QVM16.0.Malware.Gen, HEUR/QVM11.1.Malware.Gen
50.00%

avast!
Malware-gen, PUP-gen [PUP], Win32:Malware-gen, Win32:Trojan-gen, Win32:PUP-gen [PUP]
46.88%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize, UDS:DangerousObject.Multi.Generic, not-a-virus:AdWare.Win32.Amonetize
28.13%

Baidu Antivirus
Adware.Win32.Amonetize, PUA.Win32.Amonetize, PUA.Win32.AskToolbar
28.13%

NANO AntiVirus
Trojan.Nsis.Amonetize.dnxabb
25.00%

McAfee
Artemis!8EFE087C46A4, Artemis!085E52E743A9, Artemis!B32827EEAE1D, Artemis!66E18A4F12C1, Artemis!0C0D5116F37F, Artemis!8E5562B35464
21.88%

K7 AntiVirus
Adware
18.75%

Avira AntiVirus
Adware/Amonetize.289069, Adware/Amonetize.289159, ADWARE/AgentCV.A.11149, Adware/AgentCV.A.8508, ADWARE/AgentCV.A.11195
15.63%

G Data
Gen:Trojan.Heur2.FU.jD0@ayM0@hci, Win32.Trojan.Agent.K8TH6Q, Win32.Trojan.Agent.UXDSGZ
9.38%

ESET NOD32
Win32/Amonetize.DJ potentially unwanted, Win32/Amonetize.DK potentially unwanted
9.38%

Panda Antivirus
Generic Suspicious, Trj/CI.A
9.38%

The domain downprov.gas-split.com has been seen to resolve to the following 5 IP addresses.

December 23, 2015

October 19, 2015

August 11, 2015

May 4, 2015

May 4, 2015

File downloads found at URLs served by downprov.gas-split.com.

6 / 68      (inconclusive)

3 / 68      (inconclusive)
http://downprov.gas-split.com/p/.../curtain call the hits zip_10924_i23398678_il345.exe  (asus live update wont download_10924_i23398770_il345.exe)

13 / 68    (PUP)
http://downprov.gas-split.com/p/.../orson pratt the seer_10924_i23190455_il345.exe  (minecraft 1.7.2 cracked [full installer] [online] [server list]_10924_i23191889_il345.exe)

7 / 68      (PUP)

8 / 68      (PUP)
http://downprov.gas-split.com/p/.../bordertown dvd torrent.zip_10924_i22731410_il345.exe  (spyhunter 4 crack serial full version free download_10924_i22737829_il345.exe)

6 / 68      (PUP)

6 / 68      (inconclusive)

6 / 68      (PUP)
http://downprov.gas-split.com/p/.../best cracked servers 1.7.10_10924_i23002580_il345.exe  (malayalam tv channels software_10924_i23004686_il345.exe)

12 / 68    (PUP)

9 / 68      (PUP)

6 / 68      (PUP)

5 / 68      (inconclusive)
http://downprov.gas-split.com/p/.../cape chemistry past papers_10924_i23035147_il345.exe  (ati radeon drivers window 7_10924_i23033195_il345.exe)

8 / 68      (PUP)
http://downprov.gas-split.com/p/.../gdz 2 klas f m rvknd l v olyanitska matematika 1384968899_10924_i22739554_il345.exe  (spyhunter 4 crack serial full version free download_10924_i22737829_il345.exe)

8 / 68      (PUP)
http://downprov.gas-split.com/p/.../définition col legno musique_10924_i22727828_il345.exe  (spyhunter 4 crack serial full version free download_10924_i22737829_il345.exe)

5 / 68      (PUP)

7 / 68      (PUP)

6 / 68      (PUP)

9 / 68      (PUP)

5 / 68      (PUP)

11 / 68    (PUP)

 
Latest 30 of 43 download URLs

The following 2 files have been seen to comunicate with downprov.gas-split.com in live environments.

URL:
http://downprov.gas-split.com/

Web server:
Apache