safedownloadsrus131.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain safedownloadsrus131.com is registered by proxy through ENOM, INC. and was originally registered in May of 2015. Currently this domain has been known to host various forms of malware. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
Arizona, United States (US)

Create date:
Friday, May 15, 2015

Expires date:
Sunday, May 15, 2016

Updated date:
Friday, May 15, 2015

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Google Safe Browsing:
phishing

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP, PUP.AdGazelle.Verified.Installer (M), PUP.AdGazelle (M)
100.00%

ESET NOD32
Win32/AdGazelle.I potentially unwanted application
8.70%

avast!
Win32:Malware-gen
8.70%

NANO AntiVirus
Riskware.Win32.Downware.drcrbc
8.70%

IKARUS anti.virus
AdWare.AdGazelle
8.70%

Dr.Web
Adware.Downware.11074
8.70%

VIPRE Antivirus
Threat.5063330
8.70%

Avira AntiVirus
W32/Neshta.a
8.70%

Malwarebytes
PUP.Optional.Downware
8.70%

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.86912
8.70%

F-Secure
Gen:Variant.Graftor.189304
8.70%

F-Prot
W32/S-6897f6c9
8.70%

Norman
Gen:Variant.Graftor.189304
8.70%

The domain safedownloadsrus131.com has been seen to resolve to the following 7 IP addresses.

May 19, 2016

April 19, 2016

April 19, 2016

February 10, 2016

February 10, 2016

July 1, 2015

July 1, 2015

File downloads found at URLs served by safedownloadsrus131.com.

1 / 68      (Adware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Adware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

URL:
http://safedownloadsrus131.com/

Title:
“Download useful programs”

Description:
“All drivers useable for download have been scanned by antivirus program. Please take the relevant adaptation according to your computers operating system .”

SSL certificate subject:
CN=ssl93532.cloudflare.com, O="CloudFlare, Inc.", L=San Francisco, S=California, C=US

SSL certificate issuer:
CN=GlobalSign Organization Validation CA - G2, O=GlobalSign nv-sa, C=BE

Web server:
cloudflare-nginx