dl.downb468.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain dl.downb468.com is registered by proxy through GODADDY.COM, LLC and was originally registered in August of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Cambridge, Massachusetts within the United States which resides on the Akamai Technologies, Inc. network.
Remove Malware from dl.downb468.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Massachusetts, United States (US)

Create date:
Wednesday, August 28, 2013

Expires date:
Friday, August 28, 2015

Updated date:
Friday, August 29, 2014

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.FIRSERIASL.Q, PUP.Installer.AppsInstallerSL.Q, PUP.Installer.EilioDevelopmentssl.R, PUP.FIRSERIASL.Q, PUP.Solimba.FIRSERIA.Bundler (M)
100.00%

VIPRE Antivirus
DownloadMR, Threat.4150696
50.00%

Dr.Web
Trojan.DownLoader11.4341, Trojan.DownLoader11.24441, Adware.Downware.1433
50.00%

Malwarebytes
PUP.Optional.AppsInstaller, PUP.Optional.Solimba, PUP.Optional.FirSeriaInstaller
50.00%

K7 Gateway Antivirus
Trojan
50.00%

NANO AntiVirus
Trojan.Win32.DownLoader11.cykqpy, Trojan.Win32.Morstar.dfgpqs, Trojan.Win32.Downware.ctidvo
50.00%

Kaspersky
not-a-virus:AdWare.Win32.Fiseria, not-a-virus:Downloader.Win32.Morstar, not-a-virus:Downloader.Win32.Firser
50.00%

Comodo Security
Application.Win32.FirseriaInstaller.IFA, Application.Win32.Solimba.LSW, Application.Win32.Solimba.J
50.00%

Sophos
Solimba Installer, PUA 'Solimba Installer'
50.00%

Avira AntiVirus
APPL/Firseria.A.20, APPL/Firseria.Gen8, TR/Crypt.ULPM.Gen
50.00%

G Data
Win32.Application.Morstar, Gen:Variant.Application.Bundler.Kazy.132995, Gen:Application.Bundler.Firseria
50.00%

Vba32 AntiVirus
Downware.Morstar
50.00%

AVG
BundleApp, Adware BundleApp_r.AV, Adware AdInstaller.Firseria
50.00%

Panda Antivirus
Trj/Genetic.gen, Trj/CI.A, Adware/Firseria
50.00%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/Fiseria.hx, Trojan[Downloader:not-a-virus]/Win32.Morstar.as, Trojan/Win32.Tgenic
50.00%

The domain dl.downb468.com has been seen to resolve to the following 8 IP addresses.

a23-62-7-25.deploy.static.akamaitechnologies.com
January 9, 2015

a23-62-7-51.deploy.static.akamaitechnologies.com
January 9, 2015

a184-51-126-43.deploy.static.akamaitechnologies.com
December 2, 2014

a184-51-126-65.deploy.static.akamaitechnologies.com
December 2, 2014

a23-0-160-11.deploy.static.akamaitechnologies.com
September 28, 2014

a23-0-160-17.deploy.static.akamaitechnologies.com
September 28, 2014

January 6, 2014

a23-67-243-41.deploy.static.akamaitechnologies.com
January 6, 2014

File downloads found at URLs served by dl.downb468.com.

1 / 68      (Adware)
http://dl.downb468.com/n/.../AVS_Media_Player.exe  (444204aa61ee1830d4830b6b1bfaadfd)

1 / 68      (Adware)
http://dl.downb468.com/n/.../CBR Reader.exe  (52b44835cb49479ad6729a757171f2b8)

32 / 68    (Adware)
http://dl.downb468.com/n/.../FLV_Media_Player.exe  (d564ef7b8c8842c8cc73f0ac54e7b138)

26 / 68    (Adware)
http://dl.downb468.com/n/3.1.26/.../Showbox Installer.exe  (4c04a7401c98018716d8da7dd68635b7)

26 / 68    (Adware)
http://dl.downb468.com/n/.../FLV_Media_Player.exe  (f29c2bfd6f678defd005a995974d1856)

1 / 68      (Adware)
http://dl.downb468.com/n/.../FLV_Media_Player.exe  (61e68fc063bc0dfedec4c37e2dc6e0ea)

The following 55 files have been seen to comunicate with dl.downb468.com in live environments.

 
Latest 20 of 55 files

URL:
http://dl.downb468.com/

Web server:
AkamaiGHost

Remove Malware from dl.downb468.com - Powered by Reason Core Security