The domain fuggdownloads102.com registered by REACTIVATION PERIOD was initially registered in February of 2015 through ENOM, INC.. Currently this domain has been known to host various forms of malware. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrant:
REACTIVATION PERIOD
Server location:
Arizona, United States (US)
Create date:
Saturday, February 21, 2015
Expires date:
Sunday, February 21, 2016
Updated date:
Sunday, April 3, 2016
ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US
Scanner detections:
Malware distribution (98% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Optional.Installer.F, Threat.Win.Reputation.IMP, PUP.Softpulse.VolvanPremium.Installer (M), PUP.AdGazelle.VerifiedInstallation.Installer (M), PUP.AdGazelle.Verified.Installer (M)
93.88%
Dr.Web
Program.Unwanted.79, Adware.Downware.11074
16.33%
avast!
Win32:Adware-gen [Adw], Win32:Malware-gen, Win32:GenMaliciousA-SFL [Adw], Win32:Adware-CTP [PUP]
16.33%
ESET NOD32
Win32/AdGazelle.J potentially unwanted application, Win32/AdGazelle.F potentially unwanted application, Win32/AdGazelle.G potentially unwanted application
16.33%
Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.85303, Gen:Variant.Adware.Graftor.189304, Gen:Variant.Adware.Strictor.86912, Gen:Variant.Razy.12004
14.29%
VIPRE Antivirus
Threat.5063330, Trojan.Win32.Generic, Threat.4657539, Threat.4150696
14.29%
Norman
Gen:Variant.Adware.Strictor.86912, Gen:Variant.Razy.12004
12.24%
Lavasoft Ad-Aware
Gen:Variant.Adware.Strictor.85303, Gen:Variant.Adware.Graftor.189304, Gen:Variant.Adware.Strictor.86912
10.20%
MicroWorld eScan
Gen:Variant.Adware.Strictor.85303, Gen:Variant.Adware.Strictor.86912
10.20%
Bitdefender
Gen:Variant.Adware.Strictor.85303, Gen:Variant.Adware.Strictor.86912
10.20%
NANO AntiVirus
Riskware.Win32.Downware.drcrbc, Riskware.Win32.Downware.drcqse, Riskware.Win32.Downware.dqyhzo
10.20%
AhnLab V3 Security
PUP/Win32.Generic
10.20%
G Data
Gen:Variant.Adware.Strictor.85303, Gen:Variant.Adware.Strictor.86912
10.20%
F-Secure
Gen:Variant.Adware.Strictor, Gen:Variant.Adware.Graftor, Variant.Razy.12004
10.20%
Avira AntiVirus
W32/Neshta.a, TR/Starter.Y
8.16%
The domain fuggdownloads102.com has been seen to resolve to the following 5 IP addresses.
File downloads found at URLs served by fuggdownloads102.com.
Latest 30 of 53 download URLs