serv.down4desk.com

OutBrowse

Domain Information

The domain serv.down4desk.com registered by OutBrowse was initially registered in March of 2014 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Sunday, March 16, 2014

Expires date:
Thursday, March 16, 2017

Updated date:
Monday, March 28, 2016

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.BONDONJOV.DD, PUP.Installer.YESapps, PUP.Installer.Outbrowse, PUP.Installer.StartNOW, PUP.Installer.FastDownloadgot, PUP.Outbrowse.Dailyappsforfor.Installer (M), PUP.Outbrowse.bestApp.Bundler (M)
100.00%

Avira AntiVirus
APPL/Downloader.Gen
80.00%

ESET NOD32
Win32/OutBrowse.BS potentially unwanted application, Win32/OutBrowse.BU potentially unwanted application
70.00%

Kaspersky
not-a-virus:Downloader.NSIS.OutBrowse
70.00%

K7 AntiVirus
Trojan , DoS-Trojan
70.00%

Trend Micro House Call
Suspici.46EFE19D, Suspici.AF8C44A8, Suspici.1DA846D1, Suspici.8D175B40, Suspici.6AAF7647
70.00%

McAfee
RDN/Generic PUP.x!csk, Program.Adware-OutBrowse.e
60.00%

AVG
Downloader, Potentially harmful program Downloader.DII
60.00%

Malwarebytes
PUP.Optional.OutBrowse
40.00%

NANO AntiVirus
Trojan.Win32.OutBrowse.dmjuro, Trojan.Win32.OutBrowse.dmxjlz, Trojan.Nsis.OutBrowse.dnorma
40.00%

AhnLab V3 Security
PUP/Win32.OutBrowse
40.00%

G Data
MemScan:Application.Bundler.JU, Win32.Application.Agent.PJ22JG, Win32.Application.Agent.K632XZ
40.00%

Fortinet FortiGate
W32/Agent.BS!tr, Riskware/OutBrowse
40.00%

Dr.Web
infected with Trojan.OutBrowse.65, infected with Trojan.OutBrowse.83
30.00%

Sophos
Generic PUA DP, Generic PUA HA
30.00%

The domain serv.down4desk.com has been seen to resolve to the following 5 IP addresses.

ec2-23-21-196-192.compute-1.amazonaws.com
April 1, 2016

ec2-204-236-219-53.compute-1.amazonaws.com
April 1, 2016

ec2-23-21-52-184.compute-1.amazonaws.com
May 4, 2015

ec2-54-243-193-107.compute-1.amazonaws.com
May 4, 2015

ec2-23-23-223-111.compute-1.amazonaws.com
May 4, 2015

File downloads found at URLs served by serv.down4desk.com.

URL:
http://serv.down4desk.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Microsoft-IIS/8.0 (ASP.NET) (Version: 4.0.30319)