sunkfile.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain sunkfile.com is registered by proxy through GODADDY.COM, LLC and was originally registered in September of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Monday, September 29, 2014

Expires date:
Thursday, September 29, 2016

Updated date:
Sunday, October 4, 2015

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Microsoft Security Essentials
Threat.Undefined
60.42%

avast!
MSIL:Solimba-Z [PUP], Win32:Adware-gen [Adw], Win32:Kukacka
60.42%

ESET NOD32
MSIL/Solimba.AH potentially unwanted application, Win32/Sality.NBA virus
60.42%

Emsisoft Anti-Malware
Application.Bundler.Morstar.L, Application.Bundler.Solimba
54.17%

Dr.Web
Adware.Downware.8808, Adware.Downware.8763, Win32.Sector.30
52.08%

Kaspersky
not-a-virus:Downloader.Win32.Morstar
50.00%

Norman
Application.Bundler.Morstar.L, Application.Bundler.Solimba.C
47.92%

AVG
Adware BundleApp_r.AV, Win32/Sality
45.83%

Reason Heuristics
PUP.Solimba.Contumar (M), PUP.Solimba.FIRSERIA.Bundler (M), PUP.Solimba.Condesti (M), PUP.Solimba (M)
39.58%

VIPRE Antivirus
Threat.4150696, Threat.4721115
25.00%

F-Secure
Riskware.Application.Bundler.Solimba, Riskware.Application.Bundler.Morstar
18.75%

Sophos
PUA 'Solimba Installer'
6.25%

McAfee
Virus.W32/Sality.gen.z
2.08%

F-Prot
W32/Sality.gen2
2.08%

The domain sunkfile.com has been seen to resolve to the following 8 IP addresses.

ip-50-63-202-39.ip.secureserver.net
November 10, 2015

ec2-52-6-62-98.compute-1.amazonaws.com
August 19, 2015

ec2-54-165-65-72.compute-1.amazonaws.com
August 19, 2015

ec2-23-21-44-29.compute-1.amazonaws.com
May 7, 2015

ec2-75-101-136-136.compute-1.amazonaws.com
May 7, 2015

ec2-54-243-233-95.compute-1.amazonaws.com
January 6, 2015

ec2-23-23-148-223.compute-1.amazonaws.com
October 20, 2014

ec2-50-17-180-253.compute-1.amazonaws.com
October 20, 2014

File downloads found at URLs served by sunkfile.com.

0 / 68
http://sunkfile.com/n/3.1.40/.../Whatsapp.exe  (5921b3a4208598177bef9c48898b5ad0)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.43/.../NET Framework 4.exe  (427d89bb4c15754e72ed70c5b3b8b040)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.43/.../NET Framework 4 web.exe  (ff499c04377043294b9f320e58c33bf8)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.44/.../UC Browser Installer.exe  (93318e03f868af626f5674d450c4e1ad)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.44/.../WhatsApp.exe  (f69e910e4c2bf09bfce543723a2ef89c)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.43/.../Company Heroes.exe  (648a479ba923d68da1bfd3941cd566b7)

0 / 68
http://sunkfile.com/n/3.1.40/.../WhatsApp.exe  (60ee059969474e7c653f83c039d72b54)

1 / 68      (Adware)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.43/.../UC Browser Installer.exe  (dbf3ca86d794aff8e8b528e37608c172)

6 / 68      (PUP)
http://sunkfile.com/n/3.1.42/.../WhatsApp.exe  (b6c998e5c4c65cc5b13d1d8edaaf79bc)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.44/.../Nominas Diez Free.exe  (58407940a0c89ae5ed1f21a87be958c3)

1 / 68      (Adware)

9 / 68      (PUP)
http://sunkfile.com/n/3.1.40/.../Carteles.exe  (6486c1a74e4a1c9cfa099fc19949eb87)

7 / 68      (PUP)
http://sunkfile.com/n/3.1.42/.../Viber.exe  (443d8b93eb7520440fca0c1d6a47c1bb)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.44/.../photoshop.exe  (9f15798ae4cbca20724b2d6d33659672)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.43/.../too many items.exe  (d0f6271c9a6576ae8c44a1af36a94a2b)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.43/.../iMessage.exe  (4258eb64636b0f9391a2deb2407477fd)

9 / 68      (PUP)

8 / 68      (PUP)

8 / 68      (PUP)
http://sunkfile.com/n/3.1.40/.../Google Chrome.exe  (a16b4252fd51246da143cacec14421c2)

8 / 68      (PUP)
http://sunkfile.com/n/3.1.42/.../Panopreter.exe  (7af1872a976c97e65f009076705873ad)

8 / 68      (PUP)
http://sunkfile.com/n/3.1.40/.../Sumatra PDF.exe  (9651dad157995de7dc7eb313f2e15a07)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.43/.../GarageBand.exe  (0f8dfe89b9f13929085388297908f76a)

9 / 68      (PUP)
http://sunkfile.com/n/3.1.42/.../SmadAv.exe  (5f60f406545d68251e1240f6a38316c8)

10 / 68    (PUP)
http://sunkfile.com/n/3.1.40/.../Talkray.exe  (bce9f7d503af66b9273bf038bf022340)

7 / 68      (PUP)
http://sunkfile.com/n/3.1.42/.../EndNote X5.exe  (300a823257fc1fbc81a6d321d35c2190)

7 / 68      (PUP)
http://sunkfile.com/n/3.1.40/.../microsoft office.exe  (065a8d36c7c5643b0adf75190ca33887)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.44/.../Carteles.exe  (257a3c4839b0554c1e0c667b6727ca8e)

8 / 68      (PUP)
http://sunkfile.com/n/3.1.42/.../Exa Check.exe  (c530e768db8e0a37731b6f3d2909bc94)

1 / 68      (Adware)
http://sunkfile.com/n/3.1.43/.../Trey Fact.exe  (bbb7262719a14b845fb2a4eaf28e11b4)

 
Latest 30 of 72 download URLs

The following 7 files have been seen to comunicate with sunkfile.com in live environments.

URL:
http://sunkfile.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)