bestgfx.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain bestgfx.com is registered by proxy through ENOM, INC. and was originally registered in December of 2009. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
Arizona, United States (US)

Create date:
Tuesday, December 15, 2009

Expires date:
Tuesday, December 15, 2015

Updated date:
Monday, November 24, 2014

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Bkav FE
W32.Clodb45.Trojan
100.00%

McAfee
Artemis!B773A2DA41C5
100.00%

Malwarebytes
PUP.Optional.ExpressFiles.A
100.00%

K7 AntiVirus
Unwanted-Program
100.00%

Trend Micro House Call
TROJ_GEN.F47V1122
100.00%

avast!
Win32:Downloader-TSH [PUP]
100.00%

Sophos
Express Files
100.00%

VIPRE Antivirus
ExpressFiles Installer
100.00%

AhnLab V3 Security
PUP/Win32.ExpressFiles
100.00%

ESET NOD32
Win32/ExpressFiles (variant)
100.00%

AVG
MalSign.Faglaro Enterprises Limited
100.00%

Reason Heuristics
PUP.FaglaroEnterprisesLimited.R
100.00%

herdProtect (fuzzy)
a variant of 2b80df6571c45c48ae793fb3a8aca31af677b1e8
100.00%

Avira AntiVirus
Adware/ExpressFiles.G
100.00%

G Data
Win32.Application.ExpressFiles
100.00%

The domain bestgfx.com has been seen to resolve to the following 2 IP addresses.

June 18, 2015

June 18, 2015

File downloads found at URLs served by bestgfx.com.

URL:
http://bestgfx.com/

Google Analytics:
UA-19027293

Title:
“Free Download AE Project Vector Stock Web Template Photoshop Via Torrent Zippyshare”

Description:
“Bestgfx - Heaven of design | Direct download link zippyshare, extabit, mediafire, rapidshare”

SSL certificate subject:
CN=sni68381.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
nginx/1.0.15 (PHP/5.2.17p1)

Twitter:
Shares:  61

Statistics above are for the previous month of March 2024.