data.express-downloader.com

Whois Privacy Corp.

Domain Information

The domain data.express-downloader.com registered by Whois Privacy Corp. was initially registered in September of 2012 through INTERNET.BS CORP.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Saint Helens, Oregon within the United States which resides on the Hosting Services, Inc. network.
Remove Malware from data.express-downloader.com - Powered by Reason Core Security
Registrar:
INTERNET.BS CORP.

Server location:
Oregon, United States (US)

Create date:
Monday, September 03, 2012

Expires date:
Thursday, September 03, 2015

Updated date:
Tuesday, August 05, 2014

ASN:
AS29854 WESTHOST - WestHost, Inc.

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.FaglaroEnterprisesLimited.R, PUP.FaglaroEnterprisesLimited.Q, PUP.FaglaroEnterprisesLimited.P, PUP.FaglaroEnterprisesLimited.m, PUP.FaglaroEnterprisesLimited.?
100.00%

Malwarebytes
PUP.Optional.ExpressFiles.A
100.00%

avast!
Win32:Downloader-TSH [PUP]
100.00%

Sophos
Express Files
100.00%

VIPRE Antivirus
ExpressFiles Installer, Threat.4783941
100.00%

AhnLab V3 Security
PUP/Win32.ExpressFiles
100.00%

ESET NOD32
Win32/ExpressFiles (variant)
91.67%

McAfee
Artemis!BA6208CB5C33, Artemis!1FBDCF9C1254, Artemis!3DF8716A2273, Artemis!062BDA96A95E, Artemis!077C56205D58, Artemis!EC35E15F5FAE, Artemis!EED57610B3C9
83.33%

Trend Micro House Call
TROJ_GEN.F47V1201, TROJ_GEN.F47V1123, TROJ_GEN.F47V1108, TROJ_GEN.F47V1118, TROJ_GEN.F47V1101, TROJ_GEN.F47V1125, TROJ_GEN.F47V1115
83.33%

McAfee Web Gateway
Artemis!BA6208CB5C33, Artemis!1FBDCF9C1254, Artemis!3DF8716A2273, Artemis!062BDA96A95E, Artemis!077C56205D58, Artemis!EC35E15F5FAE
83.33%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
75.00%

Bkav FE
W32.Clod935.Trojan, W32.Clodb54.Trojan, W32.Clod217.Trojan, W32.Clod58d.Trojan, W32.Clod5bd.Trojan, W32.Clod4a8.Trojan, W32.Clod697.Trojan, W32.Clodec9.Trojan, W32.Clod61d.Trojan
75.00%

K7 Gateway Antivirus
Unwanted-Program
66.67%

K7 AntiVirus
Unwanted-Program
66.67%

herdProtect (fuzzy)
a variant of 6818642e61ab31cab135183567c97f430a79d232, a variant of 2b80df6571c45c48ae793fb3a8aca31af677b1e8, a variant of 7a268514cfc9b35c7492a03c6bcc4e6b3d70ec7f
66.67%

The domain data.express-downloader.com has been seen to resolve to the following 2 IP addresses.

September 3, 2014

199.195.194.4.static.midphase.com
February 2, 2014

File downloads found at URLs served by data.express-downloader.com.

17 / 68    (Adware)

12 / 68    (Adware)

28 / 68    (Adware)

11 / 68    (Adware)
http://data.express-downloader.com/j5G1XmHEvEljx 1Sa9y0Y2HJoWd9pvkgc72/.../ CNmauIzbByqZzkcp0RkWqZXJxWoXS0AlV8p  (pictures_made_out_of_keyboard_symbols_copy_and_pasteictures_made_out_of_key_downloader.exe)

14 / 68    (Adware)
http://data.express-downloader.com/j5G1RHvEu1po16gfedm8M2LZpmFlrbAvK/.../NXwvUzVo=  (hdclone_free_edition_4.3.4_downloader_hu_99433.exe)

14 / 68    (Adware)

14 / 68    (Adware)

14 / 68    (Adware)

 
Latest 30 of 79 download URLs

The following file have been seen to comunicate with data.express-downloader.com in live environments.

URL:
http://data.express-downloader.com/

Title:
“Your file is ready for download”

Web server:
nginx/1.2.1 (PHP/5.4.4-14+deb7u10)

Remove Malware from data.express-downloader.com - Powered by Reason Core Security