dl.fafdmr.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain dl.fafdmr.com is registered by proxy through GODADDY.COM, LLC and was originally registered in December of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Cambridge, Massachusetts within the United States which resides on the Akamai Technologies, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Massachusetts, United States (US)

Create date:
Monday, December 14, 2015

Expires date:
Wednesday, December 14, 2016

Updated date:
Thursday, January 7, 2016

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.FIRSERIASL.J, Adware.Solimba.Installer.a, PUP.Installer.AppsInstallerSL.I, PUP.Installer.AppsInstallerSL.Q, PUP.Bundler.Solimba, PUP.Solimba.AppsInstaller.Installer (M), PUP.Solimba.AppsInst.Bundler (M), PUP.Solimba (M)
100.00%

VIPRE Antivirus
DownloadMR, Threat.4782980, Threat.4150696
44.00%

avast!
MSIL:Crypt-KA [PUP], Win32:Solimba-C [PUP], Win32:Installer-I [PUP]
40.00%

Sophos
DownloadMR, Solimba Installer, PUA 'Solimba Installer', Mal/Generic-S, PUA 'Install Core Click run software'
40.00%

Comodo Security
Application.Win32.Solimba.GW
36.00%

Dr.Web
Adware.Downware.1125, Adware.InstallCore.125, Adware.InstallCore.122
36.00%

ESET NOD32
MSIL/Solimba.AB
32.00%

Fortinet FortiGate
Adware/Solimba, Riskware/NSIS_Agent
32.00%

Malwarebytes
PUP.Optional.Solimba.mr
28.00%

Avira AntiVirus
TR/Dropper.Gen, APPL/Solimba.Gen, PUA/Solimba.Gen
28.00%

Trend Micro House Call
TROJ_GEN.F47V0620, TROJ_GEN.F47V0615, TROJ_GEN.F47V0616, TROJ_GE.9456247C
28.00%

Vba32 AntiVirus
Signed-Downware.Morstar.AppsInstallerSL, Downloader.Agent, TScope.Trojan.MSIL
28.00%

K7 AntiVirus
Unwanted-Program
24.00%

NANO AntiVirus
Trojan.Win32.Solimba.dapwtp, Riskware.Nsis.Downware.cwebzf
24.00%

Agnitum Outpost
PUA.Solimba
24.00%

The domain dl.fafdmr.com has been seen to resolve to the following 11 IP addresses.

May 20, 2016

February 25, 2016

a23-62-6-48.deploy.static.akamaitechnologies.com
April 4, 2015

a23-62-6-82.deploy.static.akamaitechnologies.com
September 18, 2014

a23-62-6-64.deploy.static.akamaitechnologies.com
September 18, 2014

July 3, 2014

a23-67-243-33.deploy.static.akamaitechnologies.com
July 3, 2014

a23-67-250-96.deploy.static.akamaitechnologies.com
April 4, 2014

a23-67-250-122.deploy.static.akamaitechnologies.com
April 4, 2014

a23-67-242-80.deploy.static.akamaitechnologies.com
November 16, 2013

a23-67-242-35.deploy.static.akamaitechnologies.com
November 16, 2013

File downloads found at URLs served by dl.fafdmr.com.

1 / 68      (Adware)
http://dl.fafdmr.com/n/.../Smart Cleaner.exe  (74340b14949f983557353f994a53b35a)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.fafdmr.com/n/.../Google Chrome.exe  (ca0d00ddcdd2caeb71bd257a083c1a44)

8 / 68      (Adware)
http://dl.fafdmr.com/n/3.0.9.2/.../Avast.exe  (be14474a5b9feaf3fa649e65409007a5)

1 / 68      (Adware)
http://dl.fafdmr.com/n/.../Kicad-v2013.05.16.exe  (17a8185ba84f23b9327f389ac010471e)

1 / 68      (Adware)

1 / 68      (Adware)

21 / 68    (Adware)
http://dl.fafdmr.com/n/3.0.15.1/.../Avast.exe  (7f9c322ed9ed2e02f84427b3838794f9)

1 / 68      (Adware)
http://dl.fafdmr.com/n/.../Google Earth.exe  (9b0db8c380c0978d36a2ce45ce03f19b)

1 / 68      (Adware)
http://dl.fafdmr.com/n/.../Skype.exe  (182b08ea29cfcfa6f1893fd4b8397859)

1 / 68      (Adware)
http://dl.fafdmr.com/n/.../Cookies.exe  (da1dc2aa16c279c65c2eb367522dc679)

1 / 68      (Adware)
http://dl.fafdmr.com/n/.../Alfajores artesanales.exe  (2c5e3ffcb2e47dbd9dfe4f94e5ef283f)

1 / 68      (Adware)
http://dl.fafdmr.com/n/.../Avast.exe  (a2edc3bd5787f47a4ec96157946187d9)

21 / 68    (Adware)
http://dl.fafdmr.com/n/.../Avast.exe  (027a62a0100a76da76d0550c4d17f060)

1 / 68      (Adware)
http://dl.fafdmr.com/n/.../GooReader 3.0.exe  (8c7724f63e96e39986eb6d74851e90e6)

1 / 68      (Adware)
http://dl.fafdmr.com/n/.../Avast.exe  (c53bbac12b86b0fa1fceac8e1bc47a6e)

8 / 68      (Adware)

21 / 68    (Adware)
http://dl.fafdmr.com/n/.../Avast.exe  (3de41aafeec6f178bdd4c4bb94580746)

21 / 68    (Adware)
http://dl.fafdmr.com/n/.../Avast.exe  (456cc352268c99370de689d339037a32)

12 / 68    (Adware)
http://dl.fafdmr.com/n/3.0.9.2/.../Mozilla Firefox.exe  (a887c64538391d2499467725ebbfc458)

21 / 68    (Adware)
http://dl.fafdmr.com/n/.../Adobe Dreamweaver.exe  (34138d5ddd7b4b3b0dc625c6004ca6a4)

19 / 68    (Adware)
http://dl.fafdmr.com/n/.../Dropbox Download.exe  (f73a807b86ba7048d49fbe3dd395c9ce)

9 / 68      (Adware)
http://dl.fafdmr.com/n/3.0.10.1/.../MathType.exe  (8203b4607903869ef3bfa9f0d25b1089)

1 / 68      (Adware)

7 / 68      (Adware)

The following 126 files have been seen to comunicate with dl.fafdmr.com in live environments.

 
Latest 20 of 127 files

URL:
http://dl.fafdmr.com/

Title:
“Loading”

Web server:
nginx/1.8.0