afr.download-stream.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain afr.download-stream.net is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Chicago, Illinois within the United States which resides on the SingleHop, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Illinois, United States (US)

Create date:
Thursday, March 22, 2012

Expires date:
Sunday, March 22, 2015

Updated date:
Tuesday, February 4, 2014

ASN:
AS32475 SINGLEHOP-INC - SingleHop

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/Bundled.Toolbar.Google, Win32/Toolbar.Babylon (variant)
94.12%

Reason Heuristics
(M), PUP.VisualTools.m, PUP.VisualTools.V, PUP.VisualTools.a
94.12%

Malwarebytes
PUP.Optional.Babylon
88.24%

SUPERAntiSpyware
PUP.Babylon/Variant, PUP.BabylonToolbar/Variant
88.24%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
88.24%

Dr.Web
Adware.Babylon.14
82.35%

K7 AntiVirus
Trojan
82.35%

NANO AntiVirus
Trojan.Win32.Agent.ctknvv
82.35%

Agnitum Outpost
PUA.Toolbar.Babylon
82.35%

Trend Micro House Call
TROJ_GEN.F47V0828, TROJ_GEN.F47V1019, TROJ_GEN.F47V1021
23.53%

McAfee
Artemis!152214D821E2, Artemis!0DF7995951F5, Artemis!6B704F7467AD
17.65%

herdProtect (fuzzy)
a variant of 54c10ead76268622b4e49ff7eb69580941fb844e
5.88%

The domain afr.download-stream.net has been seen to resolve to the following IP address.

DedLoadLM2200.babylon.com
February 6, 2014

File downloads found at URLs served by afr.download-stream.net.

URL:
http://afr.download-stream.net/

Web server:
Apache