files5.file-mirror.info

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain files5.file-mirror.info is registered by proxy through GoDaddy.com, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the SoftLayer Technologies Inc. network.
Registrar:
GoDaddy.com, LLC

Server location:
Texas, United States (US)

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.FullSpectrumInteractive, PUP.Bundler.Tightrope, PUP.DownloadAdmin.GVUTechnologies.Installer (M), PUP.DownloadAdmin.Groovecom.Installer (M), PUP.DownloadAdmin.Installer.Meta (M), PUP.DownloadAdmin.Grooveco.Installer (M), PUP.Tightrope.Zoobam.Bundler (M), PUP.DownloadAdmin.Recode.Installer (M), PUP.Tightrope.Download.Bundler (M), PUP.DownloadAdmin.GVUTechn.Installer (M), PUP.DownloadAdmin.FullSpec.Installer (M), PUP.Fintech.Installer (M), PUP.Tightrope.Sanflex.Bundler (M), PUP.DownloadAdmin (M), PUP (M), PUP.Tightrope (M)
98.00%

F-Secure
Application:W32/Generic.70053c248f!Online, Adware:W32/WebInstallBundle
4.00%

VIPRE Antivirus
Threat.4783369, DownloadAdmin
4.00%

NANO AntiVirus
Riskware.Nsis.Downware.dlgjls, Trojan.Win32.Downware.crgjbr
4.00%

Sophos
PUA 'Download Admin'
4.00%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A
2.00%

avast!
Rootkit-gen [Rtk]
2.00%

Dr.Web
Adware.Downware.2220
2.00%

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application
2.00%

K7 AntiVirus
Unwanted-Program
2.00%

AVG
InstallC
2.00%

herdProtect (fuzzy)
a variant of ee3f6e8e244c21ed5961a90da6876b03284f37cc
2.00%

Malwarebytes
PUP.Optional.DownloadAdmin
2.00%

ESET NOD32
Win32/DownloadAdmin
2.00%

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
2.00%

The domain files5.file-mirror.info has been seen to resolve to the following 4 IP addresses.

50.22.63.138-static.reverse.softlayer.com
August 26, 2014

50.22.63.140-static.reverse.softlayer.com
August 26, 2014

50.97.63.217-static.reverse.softlayer.com
February 17, 2014

108.168.160.45-static.reverse.softlayer.com
February 17, 2014

File downloads found at URLs served by files5.file-mirror.info.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://files5.file-mirror.info/youdownloaders?id=217  (surgeonsimulator2013-setup.exe)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://files5.file-mirror.info/youdownloaders?id=225  (multiplyroi_instagram-downloader.exe)

1 / 68      (PUP)

1 / 68      (Adware)

1 / 68      (Adware)
http://files5.file-mirror.info/dl?bc=851717&type=Mahjong World  (mahjongworldexentforfreeridegames-setup.exe)

1 / 68      (PUP)

1 / 68      (Adware)

1 / 68      (Adware)

2 / 68      (false positives)

10 / 68    (PUP)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (PUP)

1 / 68      (Adware)

1 / 68      (Adware)

 
Latest 30 of 242 download URLs

The following 236 files have been seen to comunicate with files5.file-mirror.info in live environments.

 
Latest 20 of 319 files