Download
Community
knowledgeBase
» www.flashdownloadtours.com
Overview
Analysis
IPs Addresses (10)
Downloads (24)
Network (36)
www.flashdownloadtours.com
Domain Information
Server location:
Oregon, United States (US)
ASN:
AS16509 AMAZON-02 - Amazon.com, Inc., US
Root domain:
flashdownloadtours.com
Analysis
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.InstallCore.AC.Installer (M), PUP.InstallCore.AC (M)
91.67%
ESET NOD32
Win32/Sality.NBA virus
8.33%
F-Prot
W32/Sality.gen2, W32/Sality.E.gen
8.33%
AVG
Win32/Sality
8.33%
Microsoft Security Essentials
Threat.Undefined
8.33%
avast!
Win32:SaliCode, Win32:Kukacka
8.33%
Emsisoft Anti-Malware
Win32.Sality
4.17%
Norman
Win32.Sality.3
4.17%
IPs Addresses
The domain www.flashdownloadtours.com has been seen to resolve to the following 10 IP addresses.
52.36.112.186
ec2-52-36-112-186.us-west-2.compute.amazonaws.com
August 25, 2016
54.200.224.121
ec2-54-200-224-121.us-west-2.compute.amazonaws.com
August 7, 2016
54.148.57.212
ec2-54-148-57-212.us-west-2.compute.amazonaws.com
August 7, 2016
54.69.198.37
ec2-54-69-198-37.us-west-2.compute.amazonaws.com
August 7, 2016
52.41.114.34
ec2-52-41-114-34.us-west-2.compute.amazonaws.com
August 7, 2016
52.38.209.219
ec2-52-38-209-219.us-west-2.compute.amazonaws.com
August 7, 2016
52.33.46.229
ec2-52-33-46-229.us-west-2.compute.amazonaws.com
August 7, 2016
52.24.26.116
ec2-52-24-26-116.us-west-2.compute.amazonaws.com
August 7, 2016
52.10.159.134
ec2-52-10-159-134.us-west-2.compute.amazonaws.com
August 7, 2016
54.148.183.210
ec2-54-148-183-210.us-west-2.compute.amazonaws.com
August 7, 2016
Downloads
File downloads found at URLs served by www.flashdownloadtours.com.
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=iYlkqMp26dVrA2QIBCNmYZtPDUSDoxOModCo18UHsJQ=&c=enqHk11bGbEiKI7cfMQ dJ01Vr HOugKh9KUZ51cjZ0x7kUTqcdTCdhAJM9VhfVCE5nvGAcwoVng9dAb60chKvLKpSTMdj9qsbjbKVAk0bQG2ZdbTKYh7Jh2 mJz3wi1&downloadAs=Driver_Toolkit_85_Cr.exe&fallback_url=http://.../get.php?file=03c74bea&m3
(bfaf0fe10a02fc5e4250ad1b6766e086)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=NE4g46jeA0PG2AtHcZ92f9uTPZaC6qpaXYxINaJjq9s=&c=75 gfJqxSC2CaPicZdmCbZs/wjpTXNxvqaj00vgf8IRhvSS1IvRejozUdMoGJt4mPAersJ4i6j7gDe uhORYu naiyRyNi8XWbN3GfpU7TdyiNQ0tdPeztBYw/kQEi7/&downloadAs=uTorrent_343_Build_4.exe&fallback_url=http://.../get.php?file=38e14c20&m3
(35a39581f3ceb2c906029a52d71e4103)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=oFM8b2a3Nk4lZ3mtTDlybvJ64N34VB /VN59wiZZ9q0=&c=ENSG5LMX4Mq3sttUFQvOjFmLwRqesFp/xsyXVGFIS6gaN 8pDpsoKZM7Z/OQtLk0ZP6Uxa4N5PSzNsnozyKNbxPoHJIpWjKtX/4GrdB96Tdd6dkUrh3vxN8PIFqXiDWV&downloadAs=Avast_Premier_2015_b.exe&fallback_url=https://s01.solidfilesusercontent.com/M2FmYjRjZDk3ZjZmMjg5ZjFhYjAyNzZkM2VjZjg1YzZjMmNlYjViNToxYk1qdmY6dDJqdnM1VS00X0didHZVU21HNHFka3JEa0ZZ/.../Avast_Premier_2015_by_LeoO_Globe.rar
(c0e7c65e92f2762d5e4178ef69e7bde2)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=7pPaGyYuzb0OcelUfIw4GEBZzCLg54kO2tPFc73ROp8=&c=I0E44gH1TRku0t0YV5JzhDA WDR/ELYxgva6xhoIWzTOre7g8 ZqTUH8Ccpgsjx2jTEeuWaoys/VMJLgE9rWkBCRnnYqQ mzQCKzY/V khpqegWXZDEmWO03RT/3cDcq&downloadAs=KoreaMgcLifetime191.exe&fallback_url=http://.../get.php?file=d05a52f2&m3
(3c3f49a3c0627dd48cb3101df1b4de4b)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=2Ge9v4pbg5VQwOlUIV2tCTxKeocUjz1657Ddjsbu9F4=&c=v4PF3SpFVaRzUUUvPXLAqO15S//VgSC1wviyfA306qJJ7F5AnR0teJO8IB1h8KJeBI0ybhaaIbq5/psxJZZ9U77XmrHLrexksS3L03GOOStqVXQ812vT2btmuzrZJKnP&downloadAs=The_BOLT_series_23.exe&fallback_url=http://.../get.php?file=b6648b71&m3
(ca95bd70dc9f4b2380303cd010579ffc)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=5S7a81iRSjv8cUp8V8pw9xD0FjdsQoBDcAalSBgBfgM=&c=ksgzjIrgEFaM5Xau3s/XnJnd3J88BarQu5xnmfwDdVVDCDqhIpKXq/CyCGdeW04JYszw4NzyAD6M2rWBO6fX7F0j7MNPICYGlCYbFYwSuCUVreNvTeF7Lw85gEWxJDP5&downloadAs=AA-Inkling.exe&fallback_url=https://s02.solidfilesusercontent.com/ZDBkMDc2YzEyYzEwYjBkYWY3MTQyYzRlZjU3MGI4ODdlODRkZjZiMzoxYk1mSzg6Z2FneVJ5eHNLekZ2aXFCdGtjOU5iV1NLNTh3/.../AA-Inkling.rar
(ad5dedbf5fa231de5041bbe80e55b0b6)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=BGzb9TG0jA9hlLFYYVJjKx6QCtdYW2YN3PAcDc4awMo=&c=dSTMjEwDWkhuR8DHj4r0Zf1pHJsQ7JCZicAOnqk4gE3SKCz0k xEy5615Hh W06D7M gyzoh7rGaIBaaJQFWp1/1dqllGTc 2MnIVlj02xCsflOE8L8KRXbVVu9QMhr5&downloadAs=no_error_in_gta_4.exe&fallback_url=http://.../get.php?file=b9fe9e0a&m3
(ee23fa86aae1a68f93270c9b7918e4d2)
7 / 68 (Infected)
http://www.flashdownloadtours.com/c?x=qZxBJ8NWY/7cNCZpnDOyf5nyrMXf5 jcj/OZPzOe0Xs=&c=4dihGjb8wQsCyAn/WvtZU7KaXVaNBMgzEEhLOSocMKM eO5rOeiJpf4f5vgFac/G28rkDOtGIRtVLlJ5E9O/Uop2YnJM8lOj1IDTmJULxh8cel3QhX U6RWlLVPvbqG8&downloadAs=MT_PAPA_ACTION_REPLY.exe&fallback_url=http://.../get.php?file=7bfc1559&m3
(2d68918f2f1174aac1c7603e4647bac8)
5 / 68 (Malware)
http://www.flashdownloadtours.com/c?x=hfQYTVe/4177TxMXgzuhCRIvbzU 1btgRknZKu4LOmY=&c=Ab2r4DAzXK74QHOkf3Fh3b/tWi j etWFDh0d8KTseDI7aIWFU2Oesi CePC3Ab053sJfIq8Ifkg4Dw3PhFBleeR9rDyzsQ43aXMOP5EUOb/ajOvxsgDoe7d LBWDOUE&downloadAs=WTF_-_NCIKA_prod_by_.exe&fallback_url=http://.../get.php?file=a03ba809&m3
(dba0e2fb50d892646a58215b5958bb89)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=2XJ0 Zoj3LdppnhK1tJV2AXtNyzTq/jFf7auaoXPATY=&c=ofuT6wSommnsWDbHGQRjAiv2HRGyxEcfwL7T04R7Gze3ORou0bHUywv2SOrn3AKOpIPL2KatNCoyays4DAsn/mIe EzXEntbFSax6RFnY52WXI0Om4uTx2gD/mh1ftEK&downloadAs=adaptive-scalper-ea.exe&fallback_url=http://.../get.php?file=34e46376&m3
(3386c8c3b97e0f75f25e760a8a63b278)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=im8fGMG59tynA7Jrz00XhRpL2X/vJzR3V7 c0wTgQjk=&c=anhDvVyCyzTUzHolYoX98df0D kFdP7Y83TIQ7A7sslQbX47ql9CwKJ TYQwGDIeaIwslZ2Si4DZINHelyNh5t3r1pxkxGCPt4aq7VUR2aszdphprS4PD CTUl0yx9kh&downloadAs=Mosh_Prod_Subs.exe&fallback_url=http://.../get.php?file=feffeafb&m3
(6610c00b-6c18-666a-5128-864d440d225e_1c10af216b384a2)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=sVLrb57MOsWcT87KjxWDHOUZlRi9JtxhMtVz4f7tOCM=&c=0VarEd KzYoKkZ/MJ6cRGuzyYVouCdgRY9HdPrQ4NeWHUTmyqIzvF 1eRcJSRav/sn5AEok7tE18AG7n9lRI7bqEpwlLOiX kgDCZ3F MsxDtiLGAAl2gsvU8tirvaoh&downloadAs=scriptfiles.exe&fallback_url=https://s01.solidfilesusercontent.com/YzQ4NzU2N2E2NDFiNjBlNmE4ODhlNzY1YjEzZWIwYzA1ZDFmM2RiNzoxYk1maDY6MmZKdmZ3Nm5LWVRxeHRaVldFbWNjV3dEUlVr/.../scriptfiles.rar
(a4e238a291ae4f47d85c5b1cb5413715)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=NbfOLXE2/wNz4onE34QfteMtKLrfX EkmT0M xhMpDk=&c=hKgfUfNf7qgws9l4HPk0Ytjb1WKdi0JfLYbsBy8MKmndI/fM9q1Ys1cVjQgI/8/WnMcWJLXFPx6 Vyem13HQfj5HyYZ17UqeDaEUjwI4FkQl093zvUYsM ja RgB7AA3&downloadAs=Heart_fm_THB_1_July-.exe&fallback_url=http://.../get.php?file=549f7d35&m3
(e9739c86caa9cf01feae5c22f1ebdf14)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=gufLlhnoPesdJqWLEUo52NKCX3/2osq496UFIRCoORU=&c=bWUxtQYxAyhkz7z13EHQ3EW/oTlu4SUKM/ZY825aSh5fspRkmXvVrBajVGj2HrVyMFI674qHayAIl7EU1ctoOWrhMudCFfIpRRr/1bDQmMdoBSSeVoGcgR5gqYbV018m&downloadAs=Jenifa-s-Diary-Seaso.exe&fallback_url=http://.../get.php?file=87856cbb&m3
(99465ebcab52c4a4568f5d28da925c4c)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=t7qolEJ47iQUhXzNT8TW0mpuKt3 GMbEvRR8DqE20i4=&c=CZRXmL6uWki4kibe4QkY/pd0VXmRs9QDR9JmsN6rjM3rjvwjAP/jINeM4GomiR5qx7nc3/GENcnhNFoGAkXD0gCIaaU45JI0JwqQ9YNNAz IMS0soxpl7iYc9UfyKZ2u&downloadAs=UncontrollablyFondE0.exe&fallback_url=https://s02.solidfilesusercontent.com/ZDg3NmQ0MWE4Y2U2ZjE1ZjdmOTZjNTE3NDFhYjkxN2QyODU4MDhlZDoxYk1kWVc6T3luOWNoaUFDMXBPNFc3MmZJM1BjVjdDZlE4/.../Uncontrollably.Fond.E02.480p-Kshowsubindo.Net.mp4
(8f23b12d925c32c7de6d381edbd7a5a4)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=/0F47pXrEie7649PiP3VL8/jjAd2 u/uEj3p/jmVB9U=&c=S1aRW5EouzTCn 4t bA6JKJJ6IxxK U60gUXg7/v5EzfPNvTpc8qjCAF6Uohfkis0hxpkNvepegPG4MfzQh5ZZ8/czPC/5hyA45y/ZwI1DsGcdOtLw4AEqtWSLsIIR31&downloadAs=DjQness_My_worldHous.exe&fallback_url=http://.../get.php?file=f5214b88&m3
(98339fec7ccdd8b91b98ff542ac5e3c1)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=TkYL3OncpfhWbOQB1iY 2rRB rSuLMZNK/XpG6dfkNY=&c=2hJezxJg6EzVxoYopycA9WRvd0JG0dS2RklkwQ OP0AXBLeWgSfbXUSEDF09gN8zDm6MSGnbBWUwwij/9MJ5va STay8jWDuqGyhPYAqBHg1wB1BUdCmnbZ2HdDBYyFt&downloadAs=Soulitude_and_Ginton.exe&fallback_url=http://.../get.php?file=79c0b240&m3
(6dafda4ee728b1c29e8186315b18845a)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=P7HicUPDbaWLGrNNkCFOwCUZw08JGksmLN lB UAImU=&c=3atmlaJGyIpI8EtfZp/dTCrmaYjAhHv9BlXryGdhHjx9XmIPQtCfHDZ0i020MKVCCySijzd9Pgy6cF7ytNeRJpC 6CqtKhxBY28idc3TsyLVRbpqBv5FnfpTI2gJF10&downloadAs=Alicia_Keys_-_In_Com.exe&fallback_url=http://.../get.php?file=08d75dbd&m3
(5c872ba1fb28a37c01aca79da79395fe)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=45TqdAYZiDYHbKwy6fvcKMePv4p FJ VYLZxgUmaco8=&c=T3PYIAdwEOoGl52/bQDG/UWz/jGAibK6FPIJYAwlCcCOfLBgGl9VGDeHXIjOx/TJuErqAK/1fRjjBoXMlDJ/z0qQw1FdjB770Z/gBKY6RvHkO5gJnqveSmwDoRRMRCFN&downloadAs=VPS_Projects_Decency.exe&fallback_url=http://.../get.php?file=21e4599f&m3
(b9bb4eefcfbdb9613830db6dbb4fc115)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=VQ3mXOHF7ZGHIcm9vG4bBln7LRD2swtvVTQtKvKwZo8=&c=bIpqDJdG7Aud5LYj4oaU8UNqWDSFhtf0ztJKigfSv4jAe5HHfA7VDHWFPfjYm8bPAVUMkgWLpdIf7Psr62w oa/xQX0tx/RZNZdhFVLltQgT3R YwbYl7zkaCT/dKIIN&downloadAs=VPS_Projects_Cue-Ton.exe&fallback_url=http://.../get.php?file=54b76238&m3
(e1b740bdb4c836181ef369c7d4b4bdad)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=nEjirqghuZVCAbwCIWwVBqGJZAUn7T0SdSqTHJ2RtO8=&c=qu/9WMYDgwoEkw1VMokvyb4FvKODYTpXwkhtITuY9I LTMihwDghDrguy1iy8yAMcoeiwqFAItZVmpk8JwZE7Px0q6Ijx8pSVCqh0iLXO5c6OQ9auHgJwS clDRX7YjK&downloadAs=The_GodFathers_amp_C.exe&fallback_url=http://.../get.php?file=0ae415b2&m3
(15328ef3027cf58c68b42f152c44386f)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=VKHsy78SmjtLwcvTmtB4CQuEdrrwn aHXvIuNFGB9qE=&c=hN97PULd4A97Pbfgk/vV1PAmi 2bgl627RQwUqX6YJB2MM8OhAiyD7gl9lAD18hK4 tujw1udc9dQOXiwWi7pNDZmddxOLYan0qLcF0Vr/SbnIkme3lt80aqjNrCnCzH&downloadAs=TechsNG_kingroot4-8-.exe&fallback_url=http://.../get.php?file=74258c74&m3
(9f1caeb0abf28c41c1bb9110851f4e9d)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=qnYGp9 wrBCpi6Q/HDfnJVVz 7Go3AgrMqbBiuEOgMc=&c=zgp2lrvRi1E60TJanUVFnGEdIB 6PGNgIf2VfY ivj8NWAVxvo/q5fyOlazdz2MfX 7vgltSfr45QqcEyrcF/uCom8ID2mCv eATTeZkLrVz4tjLmAfhaMeC13cLpdFi&downloadAs=Modern_Combat_4_Zero.exe&fallback_url=http://.../get.php?file=004b8c5d&m3
(ea7d8337a495f2ef88b825cd9ad83b8a)
1 / 68 (Adware)
http://www.flashdownloadtours.com/c?x=eH0PjW7Tm31QmFp/eTt 7LGkTR0UViO9yXH2kjozJzw=&c=IGxkahxXJEPdNRR SK1pyagyfYNPWkF8551j6MU4NLC80K1stelTZVCjsvscWud6nNaMh0dL9LYemEpRSfaht6NgNT 5fzkL GJI8aJxiyb9F7XEDFso6bMrA AvtY2W&downloadAs=CS2014-v10C-appzzang.exe&fallback_url=http://.../get.php?file=ee1f2773&m3
(e15e601db112b39955f7df8a44a588c3)
Network Communications
The following 36 files have been seen to comunicate with www.flashdownloadtours.com in live environments.
TCP »
52.38.209.219
:80
rlvknlg.exe (Relevant-Knowledge by TMRG)
TCP »
52.33.46.229
:80
UCBrowser.exe (UC Browser by UCWeb)
TCP »
52.33.46.229
:80
browserairexec.exe (BrowserAir by Goobzo)
TCP »
52.38.209.219
:80
UCBrowser.exe (UC Browser by UCWeb)
TCP »
52.38.209.219
:80
browserairexec.exe (BrowserAir by Goobzo)
TCP »
54.200.224.121
:80
browser.exe (Browser)
TCP »
52.24.26.116
:443
online-guardian-v2.0.9.exe
TCP »
52.24.26.116
:443
online-guardian-v2.0.9.exe
TCP »
54.200.224.121
:80
kometa.exe (Kometa by @COMPANY_FULLNAME@)
TCP »
52.38.209.219
:80
browser.exe (Browser)
TCP »
52.33.46.229
:80
citrio.exe (Citrio by CatalinaGroup)
TCP »
54.200.224.121
:80
UCBrowser.exe (UC Browser by UCWeb)
TCP »
54.200.224.121
:80
ShopAtHome_BAC_Service.exe (by ShopAtHome.com)
TCP »
54.200.224.121
:80
browser.exe (Browser)
TCP »
52.33.46.229
:80
Client.exe
TCP »
54.200.224.121
:80
kmplayer_3.8.0.123.exe.exe (The KMPlayer by PandoraTV)
TCP »
52.24.26.116
:443
rlvknlg.exe (Relevant-Knowledge by TMRG)
TCP »
52.24.26.116
:443
036629fbd4864725737a8ba8fe7e8cd6.exe
TCP »
52.33.46.229
:80
ShopAtHome_BAC_Service.exe (by ShopAtHome.com)
TCP »
52.33.46.229
:80
rlvknlg.exe (Relevant-Knowledge by TMRG)
Latest 20 of 77 files
X