dl.downloadahsaequouzet.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain dl.downloadahsaequouzet.com is registered by proxy through GODADDY.COM, LLC and was originally registered in January of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Remove Malware from dl.downloadahsaequouzet.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Monday, January 04, 2016

Expires date:
Wednesday, January 04, 2017

Updated date:
Friday, February 05, 2016

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.AppsInstallerSL.O, PUP.Installer.SETUPPROCESS.V, PUP.Installer.SETUPPROCESS.I, PUP.Installer.Firseria.Q, PUP.Installer.Firseria.K, PUP.Installer.AppsInstallerSL.M, PUP.Installer.PortalProgramas.R, PUP.Installer.SETUPPROCESS.E, PUP.Installer.Firseria.T, PUP.Installer.AppsInstallerSL.X, PUP.Installer.Firseria.J, PUP.Installer.SETUPPROCESS.P, PUP.Installer.SETUPPROCESS.N, Adware.Solimba.Installer.Q, PUP.Installer.Solimba, PUP.Bundler.Solimba, Threat.Solimba.Bundler, PUP.Solimba.Firseria.Bundler (M), PUP.Solimba.SETUPPROCESS.Bundler (M)
100.00%

VIPRE Antivirus
DownloadMR, Trojan.Win32.Generic, Threat.4782980, Threat.4150696
85.11%

Malwarebytes
PUP.Optional.InstallCore, PUP.Optional.FirseriaInstaller, PUP.Optional.BundleInstaller.A, PUP.Optional.Solimba, Trojan.Agent
82.98%

K7 Gateway Antivirus
Trojan , Unwanted-Program
82.98%

K7 AntiVirus
Trojan , Unwanted-Program
82.98%

Vba32 AntiVirus
Downware.Morstar
82.98%

AVG
BundleApp, Luhe.Fiha.A, Generic_c, MalSign.Solimba, Adware Generic_c.UC, Adware BundleApp.BL, Adware BundleApp.BI, Adware BundleApp.BP
82.98%

Sophos
Solimba Installer, PUA 'Solimba Installer'
80.85%

G Data
Win32.Application.Morstar, Application.Bundler.Firseria, Gen:Variant.Strictor.56273, Application.Bundler.DownloadMR, Application.Bundler.Morstar
80.85%

ESET NOD32
Win32/Bundled.Toolbar.Google, Win32/FirseriaInstaller (variant)
74.47%

Agnitum Outpost
PUA.Firseria, Packed/MPress
44.68%

Comodo Security
Application.Win32.FirseriaInstaller.RRB, Application.Win32.Solimba.KUY, Application.Win32.FirseriaInstaller.BCB, Application.Win32.Solimba.LKI
44.68%

Dr.Web
Trojan.DownLoader11.4114, Trojan.DownLoader11.3686, Adware.Downware.2167, Adware.Downware.2174, Adware.Downware.7829, Adware.Downware.2704
44.68%

Avira AntiVirus
APPL/Firseria.A.15, TR/Spy.AI.14318.9, APPL/Firseria.D, APPL/Firseria.C, APPL/Firseria.fvt, APPL/Firseria.A.14
42.55%

Panda Antivirus
Trj/Genetic.gen, Suspicious file, PUP/MultiToolbar.A, Generic Suspicious
40.43%

The domain dl.downloadahsaequouzet.com has been seen to resolve to the following 35 IP addresses.

February 8, 2016

unallocated.barefruit.co.uk
May 15, 2015

a23-62-6-51.deploy.static.akamaitechnologies.com
April 13, 2015

a23-62-7-48.deploy.static.akamaitechnologies.com
December 1, 2014

a23-62-7-42.deploy.static.akamaitechnologies.com
December 1, 2014

a23-62-6-88.deploy.static.akamaitechnologies.com
September 18, 2014

a23-62-6-49.deploy.static.akamaitechnologies.com
September 18, 2014

a184-51-126-49.deploy.static.akamaitechnologies.com
September 4, 2014

a184-51-126-41.deploy.static.akamaitechnologies.com
September 4, 2014

a23-0-160-72.deploy.static.akamaitechnologies.com
August 16, 2014

a23-0-160-41.deploy.static.akamaitechnologies.com
August 16, 2014

a23-67-242-9.deploy.static.akamaitechnologies.com
May 18, 2014

a23-67-243-75.deploy.static.akamaitechnologies.com
May 1, 2014

a23-67-250-113.deploy.static.akamaitechnologies.com
April 14, 2014

a23-67-250-97.deploy.static.akamaitechnologies.com
April 14, 2014

a23-67-250-130.deploy.static.akamaitechnologies.com
April 14, 2014

a23-67-250-131.deploy.static.akamaitechnologies.com
February 20, 2014

a23-67-250-98.deploy.static.akamaitechnologies.com
February 20, 2014

a23-66-230-75.deploy.static.akamaitechnologies.com
February 16, 2014

a23-66-230-72.deploy.static.akamaitechnologies.com
February 16, 2014

a23-67-244-104.deploy.static.akamaitechnologies.com
February 16, 2014

a23-67-244-130.deploy.static.akamaitechnologies.com
February 16, 2014

February 14, 2014

February 14, 2014

February 14, 2014

February 14, 2014

a23-15-8-98.deploy.static.akamaitechnologies.com
February 14, 2014

a23-15-8-40.deploy.static.akamaitechnologies.com
February 14, 2014

a23-67-243-34.deploy.static.akamaitechnologies.com
February 12, 2014

a23-67-242-128.deploy.static.akamaitechnologies.com
February 8, 2014

 
Showing 30 of 35 IP Addresses

File downloads found at URLs served by dl.downloadahsaequouzet.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.downloadahsaequouzet.com/n/.../EndNote X5.exe  (f56cc2428adedd0cacafabda73e6dcaf)

1 / 68      (Adware)

35 / 68    (Adware)

32 / 68    (Adware)

0 / 68
http://dl.downloadahsaequouzet.com/n/.../uTorrent.exe  (d3fa70ae17817773aec7bb78a97a5cf4)

27 / 68    (Adware)

27 / 68    (Adware)

29 / 68    (Adware)

34 / 68    (Adware)

30 / 68    (Adware)

30 / 68    (Adware)

22 / 68    (Adware)

6 / 68      (PUP)

22 / 68    (Adware)

26 / 68    (Adware)

1 / 68      (Adware)

22 / 68    (Adware)

25 / 68    (Adware)

26 / 68    (Adware)

22 / 68    (Adware)

19 / 68    (Adware)

10 / 68    (Adware)

10 / 68    (Adware)

10 / 68    (Adware)

 
Latest 30 of 127 download URLs

The following 764 files have been seen to comunicate with dl.downloadahsaequouzet.com in live environments.

 
Latest 20 of 772 files

URL:
http://dl.downloadahsaequouzet.com/

Title:
“Loading”

Web server:
nginx/1.8.0

Remove Malware from dl.downloadahsaequouzet.com - Powered by Reason Core Security