8f56ec5a25d50527cde0d768c7fd987b.lswcdn.net

Ocom IP B.V.

Domain Information

The domain 8f56ec5a25d50527cde0d768c7fd987b.lswcdn.net registered by Ocom IP B.V. was initially registered in August of 2010 through KEY-SYSTEMS GMBH. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Manassas, Virginia within the United States which resides on the RIPE Network Coordination Centre network.
Registrar:
KEY-SYSTEMS GMBH

Server location:
Virginia, United States (US)

Create date:
Friday, August 13, 2010

Expires date:
Saturday, August 13, 2016

Updated date:
Wednesday, December 9, 2015

ASN:
AS30633 LEASEWEB-US - Leaseweb USA, Inc.,US

Root domain:

Scanner detections:
Detections  (91% detected)

Scan engine
Details
Detections

AVG
MultiBundle, Could be an adware MultiBundle
90.91%

Reason Heuristics
Adware.Bundler (M), Adware.DownloadShield.Bundle.Installer.Meta (M), Adware.DownloadShield.Bundle.Meta (M), Adware.Downloader (M)
59.09%

NANO AntiVirus
Riskware.Nsis.Dloader.dvvnkj
36.36%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
36.36%

ESET NOD32
Win32/DownWare.AO potentially unwanted application, Win32/DownWare.AR potentially unwanted application
36.36%

ESET NOD32
Win32/DownWare.AO potentially unwanted, Win32/DownWare.AR potentially unwanted
27.27%

avast!
Win32:Malware-gen, Evo-gen [Susp], Win32:Evo-gen [Susp]
27.27%

IKARUS anti.virus
AdWare.MultiBundle
27.27%

Clam AntiVirus
Win.Trojan.Agent-963992
27.27%

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen, HEUR/QVM20.1.0000.Malware.Gen
22.73%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4657539
18.18%

McAfee
Artemis!D1E3750EC6EE, Artemis!8A53C815B446
9.09%

AegisLab AV Signature
Multibundle.Gen!c
9.09%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A
4.55%

F-Secure
Application:W32/Generic.70053c248f!Online
4.55%

The domain 8f56ec5a25d50527cde0d768c7fd987b.lswcdn.net has been seen to resolve to the following 20 IP addresses.

April 12, 2016

April 9, 2016

April 9, 2016

April 9, 2016

April 9, 2016

April 9, 2016

April 9, 2016

February 23, 2016

February 23, 2016

February 23, 2016

February 23, 2016

February 23, 2016

February 23, 2016

January 4, 2016

January 4, 2016

January 4, 2016

January 4, 2016

January 4, 2016

January 4, 2016

January 4, 2016

File downloads found at URLs served by 8f56ec5a25d50527cde0d768c7fd987b.lswcdn.net.

3 / 68      (PUP)

5 / 68      (PUP)

6 / 68      (PUP)

3 / 68      (PUP)

8 / 68      (PUP)

7 / 68      (PUP)

2 / 68      (false positives)

3 / 68      (PUP)

2 / 68      (PUP)

0 / 68

11 / 68    (PUP)

9 / 68      (PUP)

3 / 68      (PUP)

2 / 68      (false positives)

3 / 68      (PUP)

2 / 68      (false positives)

3 / 68      (PUP)

4 / 68      (PUP)

3 / 68      (PUP)

6 / 68      (PUP)

2 / 68      (false positives)

9 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (PUP)

2 / 68      (PUP)

URL:
http://8f56ec5a25d50527cde0d768c7fd987b.lswcdn.net/

Title:
“404 Not Found”

SSL certificate subject:
CN=*.lswcdn.net, OU=COMODO SSL Wildcard, OU=Hosted by LeaseWeb Global Services B.V., OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
leasewebcdn/4.0.0