uni.files-fast.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain uni.files-fast.net is registered by proxy through GODADDY.COM, LLC and was originally registered in June of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Tuesday, June 3, 2014

Expires date:
Wednesday, June 3, 2015

Updated date:
Tuesday, June 3, 2014

ASN:
AS16265 FIBERRING LeaseWeb B.V.,NL

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MaxigetLimited.f, PUP.MaxigetLimited.e, PUP.MaxigetLimited.AA, PUP.MaxigetLimited.Q, PUP.MaxigetLimited.a, PUP.MaxigetLimited.N, PUP.New IT Limited.MaxigetLimited, PUP.New IT Limited.Maxiget (M), PUP.New IT Limited.Maxiget.Bundler (M), PUP.New IT Limited (M)
100.00%

VIPRE Antivirus
Threat.4150696
25.00%

ESET NOD32
Win32/4Shared.U potentially unwanted application, probably Win32/4Shared.X potentially unwanted application, Win32/4Shared.AD potentially unwanted application
25.00%

McAfee
PUP-FIW, 4shared, Program.4shared, Program.PUP-FNX
25.00%

Agnitum Outpost
PUA.4Shared, PUA.Downloader
25.00%

Sophos
4Share Downloader, PUA.4Share Downloader, PUA '4Share Downloader'
25.00%

Avira AntiVirus
APPL/Downloader.Gen, APPL/4Shared.X.85, APPL/Downloader.Gen8, APPL/Maxiget.36864
25.00%

G Data
Win32.Application.4shared, Application.Generic.932567, Application.Generic.957024
25.00%

AVG
Generic
25.00%

Dr.Web
Adware.Downware.1751
22.22%

K7 AntiVirus
Unwanted-Program , Trojan
22.22%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, Downloader.AdLoad, Downloader.GetFaster
19.44%

F-Prot
W32/A-5663f742, W32/A-f1b4f386, W32/A-e4be085e, W32/A-083dbbf9
19.44%

NANO AntiVirus
Riskware.Win32.Downware.decuce, Trojan.Win32.AdLoad.dgahty, Riskware.Win32.Downware.degjpe
19.44%

Zillya! Antivirus
Downloader.Adload.Win32.17712, Backdoor.PePatch.Win32.43863, Downloader.GetFaster.Win32.78
19.44%

The domain uni.files-fast.net has been seen to resolve to the following 3 IP addresses.

hosted-by.leaseweb.com
January 12, 2015

August 1, 2014

August 1, 2014

File downloads found at URLs served by uni.files-fast.net.

1 / 68      (Adware)
https://uni.files-fast.net/.../Hatouli.Ragel.2013.exe  (fd6c603d832e9b6a7d25676f82796b78)

1 / 68      (Adware)
https://uni.files-fast.net/.../DJ Doncho, Alex Raeva - ...(5prite Dirty Remix).exe  (dj doncho, alex raeva -...(5prite dirty remix).exe)

1 / 68      (Adware)
https://uni.files-fast.net/.../Dreamworks.exe  (be4b44fb28c7b0efa641d58caf4f3192)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
https://uni.files-fast.net/.../7.r.Pre.DVDRip.exe  (89348e2e7c19ce4d95ac48620642c415)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
https://uni.files-fast.net/.../TPOMK.myEGY.to.exe  (564d09188baee3bc69e91c432995fb46)

1 / 68      (Adware)
https://uni.files-fast.net/.../????????????????????????...????????????????????.exe  (【斉藤一人】精神論を超えた不思議とダメの壁を乗り...分を潜在意識から肯定する知らないと損する.exe)

1 / 68      (Adware)

1 / 68      (Adware)
https://uni.files-fast.net/.../id21.10.MR.!.HERO.exe  (acfea476df441a90e3a24c7350bb6290)

1 / 68      (Adware)
https://uni.files-fast.net/.../MyEgy.W.P.720p.Elk!ng.exe  (aac32f64f319fe87d52346dcee4c41e7)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
https://uni.files-fast.net/.../Samira.Said.Elly.Benna.exe  (d1433fe634009e0bcb905da9bcd9d78d)

1 / 68      (Adware)

1 / 68      (Adware)
https://uni.files-fast.net/.../Salem.Abo.Okhto.exe  (00d3a15482ab847656d93ce788695ba4)

1 / 68      (Adware)

1 / 68      (Adware)
https://uni.files-fast.net/.../WUCCalculator_v4.4.exe  (d917e70e9b6b25f93bb8477773045755)

1 / 68      (Adware)
https://uni.files-fast.net/.../iEx3321.exe  (bf163e709b4b7b3ef73523135033712b)

1 / 68      (Adware)
https://uni.files-fast.net/.../PhotoScan.Pro.1.0.4.exe  (73cf2a78350ba109d35c11d68bb8c7ef)

17 / 68    (Adware)

16 / 68    (Adware)

25 / 68    (Adware)

26 / 68    (Adware)
https://uni.files-fast.net/.../FIFA_12_CRACK.exe  (6b4232b74f3bbd6aaafd2906c3e28761)

 
Latest 30 of 36 download URLs

The following 18 files have been seen to comunicate with uni.files-fast.net in live environments.

 
Latest 20 of 22 files

URL:
http://uni.files-fast.net/

Google Analytics:
UA-41200419

Title:
“GetDownload CDN Network”

SSL certificate subject:
CN=ssl2020.cloudflare.com, O="CloudFlare, Inc.", L=San Francisco, S=CA, C=US

SSL certificate issuer:
CN=GlobalSign Organization Validation CA - G2, O=GlobalSign nv-sa, C=BE

Web server:
cloudflare-nginx

30 of 31 related domains