fbdmr.line55.net

NAMECHEAP.COM

Domain Information

The domain fbdmr.line55.net registered by NAMECHEAP.COM was initially registered in February of 2009 through ENOM, INC.. Currently this domain has been known to host various forms of malware. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
Arizona, United States (US)

Create date:
Saturday, February 21, 2009

Expires date:
Thursday, February 21, 2019

Updated date:
Wednesday, November 13, 2013

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Fortinet FortiGate
W32/Downloader_x.LU!tr
100.00%

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
100.00%

MicroWorld eScan
Trojan.Generic.12194356
100.00%

nProtect
Trojan.Generic.12194356
100.00%

McAfee
RDN/Downloader.a!tx
100.00%

Malwarebytes
Trojan.Downloader.Agent
100.00%

Trend Micro House Call
TROJ_GEN.R047C0EL714
100.00%

avast!
Win32:Dropper-gen [Drp]
100.00%

Bitdefender
Trojan.Generic.12194356
100.00%

Lavasoft Ad-Aware
Trojan.Generic.12194356
100.00%

F-Secure
Trojan.Generic.12194356
100.00%

Dr.Web
Trojan.DownLoader11.39547
100.00%

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
100.00%

Trend Micro
TROJ_GEN.R047C0EL714
100.00%

Emsisoft Anti-Malware
Trojan.Generic.12194356
100.00%

The domain fbdmr.line55.net has been seen to resolve to the following 2 IP addresses.

May 5, 2015

May 5, 2015

File downloads found at URLs served by fbdmr.line55.net.

20 / 68    (Malware)
https://fbdmr.line55.net/FLV-HD.exe  (bf71e0f1521e1290ec16cf1747a0c864)

URL:
http://fbdmr.line55.net/

SSL certificate subject:
CN=sni67905.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx (PHP/5.4.34)