29f51ed1.down8bucket.us

mike peters

Domain Information

The domain 29f51ed1.down8bucket.us registered by mike peters was initially registered in September of 2014 through Internet.bs Corp.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the SoftLayer Technologies Inc. network.
Registrar:
Internet.bs Corp.

Server location:
Texas, United States (US)

Create date:
Sunday, September 28, 2014

Expires date:
Sunday, September 27, 2015

Updated date:
Sunday, September 28, 2014

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.FortySevenTechSoftware.T
100.00%

VIPRE Antivirus
Threat.4759033
100.00%

AVG
Adware InstallBrain.BA
100.00%

ESET NOD32
Win32/InstallBrain.BZ potentially unwanted application
100.00%

Dr.Web
Adware.Downware.8543
100.00%

Malwarebytes
PUP.Optional.CodecPerformer.A
100.00%

K7 AntiVirus
Unwanted-Program
100.00%

NANO AntiVirus
Trojan.Win32.DownLoader11.dbedcj
100.00%

Comodo Security
Application.Win32.InstallBrain.BF
100.00%

Sophos
PUA.InstallBrain
100.00%

G Data
Win32.Application.InstallBrain
100.00%

Qihoo 360 Security
Malware.QVM06.Gen
100.00%

avast!
Win32:InstallBrain-BH [PUP]
100.00%

MicroWorld eScan
Gen:Variant.Strictor.59006
100.00%

SUPERAntiSpyware
Questionable.Resource
100.00%

The domain 29f51ed1.down8bucket.us has been seen to resolve to the following 4 IP addresses.

50.97.49.243-static.reverse.softlayer.com
October 9, 2014

50.97.44.131-static.reverse.softlayer.com
October 9, 2014

174.37.181.31-static.reverse.softlayer.com
October 9, 2014

173.192.190.227-static.reverse.softlayer.com
October 9, 2014

File downloads found at URLs served by 29f51ed1.down8bucket.us.

The following 15 files have been seen to comunicate with 29f51ed1.down8bucket.us in live environments.

URL:
http://29f51ed1.down8bucket.us/

Title:
“Contact Us”

Web server:
nginx/1.2.4 (PHP/5.3.16)