www.solidfiles.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain www.solidfiles.com is registered by proxy through ENOM, INC. and was originally registered in July of 2008. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Bucharest, Bucuresti within Romania which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Bucuresti, Romania (RO)

Create date:
Wednesday, July 16, 2008

Expires date:
Sunday, July 16, 2017

Updated date:
Tuesday, September 22, 2015

ASN:
AS3223 VOXILITY Voxility S.R.L.,RO

Root domain:

Scanner detections:
Detections  (91% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Somoto.i, PUP.Somoto.SomotoIsrael.Bundler (M), PUP.Somoto.SITEONSPOT.Bundler (M), PUP.Somoto.Bundler (M), PUP.Solimba.Contumar (M), PUP.Solimba.DelimaxC (M), PUP.Somoto.SomotoIs.Bundler (M), PUP.Solimba.DanorelI (M), PUP.Somoto.SITEONSP.Bundler (M), Adware.Somoto.ZettlyHa.Installer.Meta (M), PUP.Somoto (M), PUP.Solimba (M), Adware.Somoto (M)
97.73%

SUPERAntiSpyware
PUP.Somoto/Variant, Trojan.Agent/Gen-Autorun[VB]
4.55%

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen, HEUR/QVM03.0.Malware.Gen
4.55%

K7 AntiVirus
Unwanted-Program
2.27%

NANO AntiVirus
Riskware.Nsis.Adware.dbnhrj
2.27%

avast!
Win32:Somoto-R [PUP]
2.27%

Clam AntiVirus
Win.Adware.Somoto
2.27%

Sophos
Somoto BetterInstaller
2.27%

Comodo Security
Application.Win32.Somoto.CK
2.27%

Dr.Web
Trojan.Packed.28357
2.27%

VIPRE Antivirus
Trojan.Win32.Generic
2.27%

Avira AntiVirus
APPL/Somoto.Gen2
2.27%

AhnLab V3 Security
Win-PUP/Somoto
2.27%

ESET NOD32
Win32/Somoto
2.27%

AVG
Generic
2.27%

The domain www.solidfiles.com has been seen to resolve to the following 4 IP addresses.

lh25696.voxility.net
October 1, 2015

lh27200.voxility.net
August 11, 2015

lh26231.voxility.net
November 10, 2014

lh22551.voxility.net
February 15, 2014

File downloads found at URLs served by www.solidfiles.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

0 / 68

1 / 68      (Adware)
http://www.solidfiles.com/.../WL_downloader-a66og12m.exe  (32ff6c8511238ee46668725ba59e5ef9)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://www.solidfiles.com/dlm/sol/.../?host=s26.solidfilesusercontent.com  (_awsubs__shingeki_no_kyojin_-_ova_2__480p__96b78f14_.mkv.exe)

1 / 68      (Adware)
http://www.solidfiles.com/dlm/sol/.../?host=s9.solidfilesusercontent.com  (_awsubs__shingeki_no_kyojin_-_ova_03__480p__da97acaf_.mkv.exe)

1 / 68      (Adware)

1 / 68      (Adware)

0 / 68

1 / 68      (Adware)

1 / 68      (Adware)

2 / 68

16 / 68    (Adware)
http://www.solidfiles.com/.../ATKSGHN96_downloader-Qe13sktlj.exe  (download-freakshare_downloader-icb6rpo1f.exe)

16 / 68    (Adware)
http://www.solidfiles.com/.../IDM_6_downloader-I44Zrk64w.exe  (download-freakshare_downloader-icb6rpo1f.exe)

16 / 68    (Adware)
http://www.solidfiles.com/.../R-JSC_downloader-I7dNwUL9v.exe  (download-freakshare_downloader-icb6rpo1f.exe)

1 / 68      (Adware)

1 / 68      (Adware)

16 / 68    (Adware)
http://www.solidfiles.com/.../Mozilla-US_downloader-Q5PJ6HrvF.exe  (download-freakshare_downloader-icb6rpo1f.exe)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

0 / 68

1 / 68      (Adware)

 
Latest 30 of 395 download URLs

The following 11 files have been seen to comunicate with www.solidfiles.com in live environments.

 
Latest 20 of 40 files

URL:
http://www.solidfiles.com/

Google Analytics:
UA-12863264

Title:
“Solidfiles - Free File Hosting - Upload Your Files”

Description:
“Solidfiles is a free service used to download, upload and share files with friends, colleagues and the world.”

SSL certificate subject:
CN=*.solidfiles.com, OU=PositiveSSL Wildcard, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
nginx

Facebook:
Likes:  435
Shares:  259
Comments:  155

Statistics are for the previous month.