kph.downloadget.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain kph.downloadget.net is registered by proxy through GODADDY.COM, LLC and was originally registered in August of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in West McLean, Virginia within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Thursday, August 15, 2013

Expires date:
Saturday, August 15, 2015

Updated date:
Tuesday, October 14, 2014

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MaxigetLimited.CC, PUP.MaxigetLimited.T, PUP.New IT Limited (M)
100.00%

ESET NOD32
probably Win32/4Shared.X potentially unwanted application
66.67%

VIPRE Antivirus
Threat.4150696
66.67%

Kaspersky
not-a-virus:Downloader.Win32.AdLoad
66.67%

Dr.Web
Adware.Downware.1751
66.67%

McAfee
4shared
66.67%

Malwarebytes
PUP.Optional.Elite
66.67%

Zillya! Antivirus
Downloader.Adload.Win32.17712
66.67%

K7 AntiVirus
Unwanted-Program
66.67%

NANO AntiVirus
Trojan.Win32.AdLoad.dgahty
66.67%

F-Prot
W32/A-f1b4f386
66.67%

Clam AntiVirus
Win.Trojan.4shared-26
66.67%

Agnitum Outpost
PUA.Downloader
66.67%

Sophos
4Share Downloader
66.67%

Avira AntiVirus
APPL/Downloader.Gen8
66.67%

The domain kph.downloadget.net has been seen to resolve to the following 2 IP addresses.

October 20, 2014

October 20, 2014

File downloads found at URLs served by kph.downloadget.net.

18 / 68    (Adware)

18 / 68    (Adware)

URL:
http://kph.downloadget.net/

Google Analytics:
UA-41200419

Title:
“GetPortal CDN Network”

SSL certificate subject:
CN=ssl4516.cloudflare.com, O="CloudFlare, Inc.", L=San Francisco, S=CA, C=US

SSL certificate issuer:
CN=GlobalSign Organization Validation CA - G2, O=GlobalSign nv-sa, C=BE

Web server:
cloudflare-nginx

30 of 31 related domains