www.1freedown.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.1freedown.com is registered by proxy through GODADDY.COM, LLC and was originally registered in June of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Monday, June 3, 2013

Expires date:
Friday, June 3, 2016

Updated date:
Tuesday, April 14, 2015

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US

Root domain:

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
(M), PUP.OUTBROWSE.M, PUP.OUTBROWSE.G, PUP.Outbrowse.Bundler (M), PUP.OutBrowse (M), PUP.Air Software.AirSoftw.Bundler (M)
60.00%

Dr.Web
Adware.Downware.1770, Adware.Downware.2081, Adware.Downware.1676, Adware.Conduit.14, Trojan.DownLoader11.31922, Threat.Undefined
56.67%

VIPRE Antivirus
OutBrowse, Adware.OutBrowse, Trojan.Win32.Generic, Threat.4784459, Threat.4150696
50.00%

NANO AntiVirus
Trojan.Win32.OutBrowse.csrlza, Trojan.Win32.Generic.cthmwf, Trojan.Win32.Generic.dbxkzp, Trojan.Win32.OutBrowse.cxaakt
40.00%

Avira AntiVirus
W32/Mabezat, APPL/OutBrowse.A, APPL/Downloader.Gen, APPL/Downloader.F.6, PUA/Outbrowse.Gen
36.67%

avast!
Win32:PUP-gen [PUP], Win32:Malware-gen, Win32:Adware-gen [Adw], OutBrowse-EG [PUP], Win32:OutBrowse-G [PUP]
36.67%

McAfee
RDN/Generic PUP.x!bw3, Adware-OutBrowse, RDN/Generic PUP.x!b2f, Artemis!9DDCBF0D0925, RDN/Generic PUP.x!bzp, Program.Adware-OutBrowse
33.33%

AhnLab V3 Security
PUP/Win32.OutBrowse
33.33%

Kaspersky
not-a-virus:Downloader.NSIS.OutBrowse, not-a-virus:AdWare.Win32.OutBrowse
30.00%

ESET NOD32
Win32/OutBrowse (variant), Win32/OutBrowse.BA potentially unwanted (variant)
30.00%

AVG
MalSign.OutBrowse, MalSign.Generic, Downloader, Win32/Heur
30.00%

Fortinet FortiGate
Riskware/NSIS_OutBrowse, Riskware/OutBrowse
30.00%

ESET NOD32
Win32/OutBrowse.W potentially unwanted application, Win32/OutBrowse.M potentially unwanted application, Win32/OutBrowse.G potentially unwanted application, Win32/OutBrowse.T potentially unwanted application, Win32/OutBrowse.Q potentially unwanted application
30.00%

Malwarebytes
PUP.Optional.OutBrowse, PUP.Optional.Smart
26.67%

K7 AntiVirus
Trojan , Unwanted-Program
26.67%

The domain www.1freedown.com has been seen to resolve to the following 3 IP addresses.

September 4, 2016

ip-184-168-221-63.ip.secureserver.net
June 24, 2016

charlie208.startdedicated.com
May 1, 2014

File downloads found at URLs served by www.1freedown.com.

2 / 68      (PUP)

4 / 68      (PUP)

3 / 68      (PUP)

1 / 68      (Adware)

2 / 68      (Malware)

1 / 68      (Adware)

1 / 68      (Adware)

2 / 68      (Malware)

30 / 68    (PUP)
http://www.1freedown.com/download/r/.../java.exe  (49b2d48bef148bea3db885a41b23b5d2)

21 / 68    (PUP)
http://www.1freedown.com/download/r/.../flash_player.exe  (47d95ff01f9a47691858bbeb5d562089)

25 / 68    (PUP)
http://www.1freedown.com/download/r/adus7/.../java.exe  (f17e71e3204e971510285dff4a812a5c)

 
Latest 30 of 37 download URLs

The following 87 files have been seen to comunicate with www.1freedown.com in live environments.

 
Latest 20 of 89 files

URL:
http://www.1freedown.com/

Title:
“1freedown.com”

Web server:
Apache (PleskLin)