files.getdownloadsnow.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain files.getdownloadsnow.com is registered by proxy through ENOM, INC. and was originally registered in September of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Digital Ocean, Inc. network.
Registrar:
ENOM, INC.

Server location:
New York, United States (US)

Create date:
Monday, September 22, 2014

Expires date:
Thursday, September 22, 2016

Updated date:
Sunday, August 23, 2015

ASN:
AS393406 DIGITALOCEAN-ASN-NY3 - Digital Ocean, Inc.,US

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.InstallX.Bundle, PUP.Air Software.DownloadManager.Bundler (M), PUP.Air Software.InstallerSetup.Installer (M), PUP.Air Software.InstallerSetup (M), PUP.Vittalia.InstallAssistant.Installer (M), PUP.Vittalia.InstallHelper.Installer (M), Threat.Win.Reputation.IMP, PUP.Bundlore.Installer.Installer (M), PUP.Air Software.Download.Bundler (M), PUP.Air Software.Installe.Installer (M), PUP.Vittalia.InstallH.Installer (M), PUP.Softpulse.Softforc.Bundler (M), PUP.Air Software (M)
100.00%

avast!
Win32:Malware-gen, Win32:Adware-gen [Adw], Win32:Adware-CJY [PUP]
38.30%

VIPRE Antivirus
Iminent, Threat.4782985
36.17%

Dr.Web
Adware.Downware.9668, Adware.Iminent.1, Adware.Downware.9532, Adware.Downware.9693
34.04%

ESET NOD32
Win32/AirAdInstaller.E potentially unwanted application
34.04%

Malwarebytes
PUP.Optional.AirAdInstaller, PUP.Optional.AirInstall
34.04%

Avira AntiVirus
ADWARE/Adware.Gen
34.04%

AVG
Generic
34.04%

Agnitum Outpost
PUA.AirAd
34.04%

AhnLab V3 Security
PUP/Win32.Installer
34.04%

IKARUS anti.virus
AdWare.AirAdInstaller, PUA.AirAdInstaller
34.04%

K7 AntiVirus
Unwanted-Program
34.04%

NANO AntiVirus
Riskware.Win32.AirAdInstaller.dlqckn, Riskware.Win32.Iminent.dkjksr
34.04%

Rising Antivirus
PE:PUF.Airinstall!1.9C4C
31.91%

McAfee
Trojan.Artemis!757FB24A0964
31.91%

The domain files.getdownloadsnow.com has been seen to resolve to the following IP address.

eus.livedigitrack.com
January 25, 2015

File downloads found at URLs served by files.getdownloadsnow.com.

 
Latest 30 of 60 download URLs