www.downloadspring.com
James Guel
Domain Information
The domain www.downloadspring.com registered by James Guel was initially registered in July of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, LLC
Server location:
Arizona, United States (US)
Create date:
Monday, July 15, 2013
Expires date:
Saturday, July 15, 2017
Updated date:
Sunday, December 8, 2013
ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC
Google Safe Browsing:
unwanted
Scanner detections:
Detections (79% detected)
Scan engine
Details
Detections
Reason Heuristics
Adware.DownloadShield.Bundle.Installer.Meta (M), PUP.DownloadShield.Installer (M), PUP.Download.Installer (M), PUP (M)
92.68%
SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
9.76%
Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
7.32%
ViRobot
Backdoor.Win32.A.BlackHole.2197393[UPX], Trojan.Win32.A.Downloader.64873[h]
4.88%
McAfee
Artemis!46E423B4733E, Artemis!EE08E021AD73
4.88%
VIPRE Antivirus
DownloadShield
4.88%
AVG
MultiBundle, Generic
4.88%
Microsoft Security Essentials
Worm:Win32/NeksMiner.A
2.44%
F-Secure
Application:W32/Generic.70053c248f!Online
2.44%
Fortinet FortiGate
Riskware/WiFiRadar
2.44%
Bkav FE
W32.Clodffd.Trojan
2.44%
Malwarebytes
PUP.Adware.Agent
2.44%
Trend Micro House Call
Suspicious_GEN.F47V0430
2.44%
Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
2.44%
The domain www.downloadspring.com has been seen to resolve to the following 3 IP addresses.
p3nlhg146c1146.shr.prod.phx3.secureserver.net
February 6, 2014
File downloads found at URLs served by www.downloadspring.com.
Latest 30 of 174 download URLs
The following 4 files have been seen to comunicate with www.downloadspring.com in live environments.
URL:
http://www.downloadspring.com/
SSL certificate subject:
CN=sni100815.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated
SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB
Web server:
cloudflare-nginx
Statistics are for the previous month.
Related Domains