dl.airdwnlds.com

Air Software  (via a Proxy Registrant)

Domain Information

The domain dl.airdwnlds.com is registered by proxy through ENOM, INC. and was originally registered in September of 2012. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Digital Ocean, Inc. network. The domain is associated with the publisher Air Software who is located in Victoria, British Columbia in Canada.
Remove Malware from dl.airdwnlds.com - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
New York, United States (US)

Create date:
Tuesday, September 11, 2012

Expires date:
Sunday, September 11, 2016

Updated date:
Wednesday, August 12, 2015

ASN:
AS14061 DIGITALOCEAN-ASN - Digital Ocean, Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.F, DownloadManager.AirSoftware.F, DownloadManager.Air Software, DownloadManager.Bundler.Air Software, PUP.Air Software.AirSoftware.Bundler (M), PUP.AirInstaller.Bundler, PUP.InstallCore.Installer.Installer (M)
100.00%

Dr.Web
Program.Unwanted.79, Adware.Downware.586, Trojan.SMSSend.4610, Trojan.SMSSend.4317, Adware.Downware.624, Trojan.SMSSend.4653
96.00%

avast!
Win32:Adware-CAH [PUP], Win32:Installer-L [PUP], Adware-gen [Adw], PUP-gen [PUP]
94.00%

Comodo Security
Application.Win32.AirAdInstaller.A, Application.Win32.AirAdInstaller.B, Application.Win32.Agent.AJ
94.00%

VIPRE Antivirus
AirInstaller, Threat.4782985, Threat.4848734, Threat.4150696
94.00%

Avira AntiVirus
Adware/AirAdInstaller.AJ.2, ADWARE/Adware.Gen7, Adware/AirInst.1174, Adware/AirAdInstaller.AB, Adware/Airinstall.J, Adware/AirAdInstaller.F
94.00%

Sophos
PUA 'AirInstaller'
94.00%

K7 AntiVirus
Riskware, Unwanted-Program , Adware
92.00%

K7 Gateway Antivirus
Riskware, Unwanted-Program , Adware
92.00%

McAfee Web Gateway
Artemis!1FD78BE53C8D, BehavesLike.Win32.Downloader.cc , BehavesLike.Win32.LiveSoftAction.cc, BehavesLike.Win32.Expiro.vh
92.00%

Rising Antivirus
PE:PUF.Airinstall!1.9C4C
92.00%

F-Prot
W32/AirInstall.A7.gen, W32/AirInstall.A.gen, W32/AirInstall.A8.gen, W32/AirInstall.C.gen
92.00%

IKARUS anti.virus
not-a-virus:AdWare.Win32, AdWare.AdWare.Gen7, AdWare.AirAdInstaller, AdWare.Airinstall, PUA.AirAdInstaller, not-a-virus:WebToolbar.Win32.Agent
92.00%

Panda Antivirus
Adware/AirInstaller, Trj/Genetic.gen
92.00%

G Data
Win32.Adware.Airadinstaller, Application.Bundler.AirInstaller
92.00%

The domain dl.airdwnlds.com has been seen to resolve to the following 9 IP addresses.

108.168.218.35-static.reverse.softlayer.com
October 9, 2014

108.168.218.34-static.reverse.softlayer.com
May 28, 2014

50.23.68.85-static.reverse.softlayer.com
May 5, 2014

chicago.airinstaller.com
April 13, 2014

justice.airinstaller.com
February 7, 2014

173.192.195.226-static.reverse.softlayer.com
February 7, 2014

empire.airinstaller.com
February 7, 2014

173.192.195.228-static.reverse.softlayer.com
February 6, 2014

uswestmeganode1.airinstaller.com
February 5, 2014

File downloads found at URLs served by dl.airdwnlds.com.

38 / 68    (Adware)

28 / 68    (Adware)

9 / 68      (Adware)

29 / 68    (Adware)

2 / 68      (PUP)

20 / 68    (Adware)

29 / 68    (Adware)

27 / 68    (Adware)

38 / 68    (Adware)

41 / 68    (Adware)

 
Latest 30 of 82 download URLs

The following 2 files have been seen to comunicate with dl.airdwnlds.com in live environments.

Remove Malware from dl.airdwnlds.com - Powered by Reason Core Security