strongdownloads.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain strongdownloads.com is registered by proxy through GODADDY.COM, LLC and was originally registered in June of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Monday, June 8, 2015

Expires date:
Wednesday, June 8, 2016

Updated date:
Monday, June 8, 2015

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Bkav FE
W32.HfsAdware
100.00%

MicroWorld eScan
Trojan.GenericKD.2532778
100.00%

Bitdefender
Trojan.GenericKD.2532778
100.00%

ESET NOD32
MSIL/Adware.Joedown (variant)
100.00%

avast!
Win32:Evo-gen [Susp]
100.00%

Kaspersky
Trojan-Dropper.MSIL.Agent.servvb
100.00%

Lavasoft Ad-Aware
Trojan.GenericKD.2532778
100.00%

F-Secure
Trojan.GenericKD.2532778
100.00%

Dr.Web
Trojan.KillFiles.18730
100.00%

Emsisoft Anti-Malware
Trojan.GenericKD.2532778
100.00%

AhnLab V3 Security
PUP/Win32.Joedown
100.00%

IKARUS anti.virus
AdWare.MSIL.Joedown
100.00%

The domain strongdownloads.com has been seen to resolve to the following 2 IP addresses.

July 16, 2015

July 16, 2015

File downloads found at URLs served by strongdownloads.com.

12 / 68    (PUP)
http://strongdownloads.com/downloader.aspx?e=0&s=2&p=0&filename=FacebookÅžifresiKırmaProgramÄ  (facebookãƒæ’ã¢â‚¬â¦ãƒâ€¦ã‚â¾ifresikãƒæ’ã¢â‚¬å¾ãƒâ€šã‚â±rmaprogramãƒæ’ã¢â‚¬å¾.exe)

URL:
http://strongdownloads.com/

SSL certificate subject:
CN=sni51586.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx (ASP.NET)