dl.s0ftohqimjjedf0jq.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain dl.s0ftohqimjjedf0jq.net is registered by proxy through GODADDY.COM, LLC and was originally registered in September of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Cambridge, Massachusetts within the United States which resides on the Akamai Technologies, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Massachusetts, United States (US)

Create date:
Thursday, September 19, 2013

Expires date:
Saturday, September 19, 2015

Updated date:
Wednesday, May 20, 2015

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.AppsInstallerSL.K, PUP.Installer.FIRSERIASL.X, PUP.Solimba.FIRSERIA.Bundler (M), PUP.Solimba (M)
100.00%

Malwarebytes
PUP.Optional.Firseria
75.00%

K7 AntiVirus
Trojan , Unwanted-Program , Backdoor
75.00%

Agnitum Outpost
PUA.Firseria, PUA.Downloader
75.00%

Sophos
Solimba Installer
75.00%

VIPRE Antivirus
DownloadMR, Threat.4782980
50.00%

Avira AntiVirus
APPL/Firseria.A.28, APPL/Firseria.A.3
50.00%

G Data
Win32.Application.Morstar, Gen:Application.Bundler.Firseria
50.00%

Vba32 AntiVirus
Downware.Morstar
50.00%

AVG
BundleApp, Adware AdInstaller.Firseria
50.00%

avast!
Win32:Firseria-A [PUP]
50.00%

Kaspersky
not-a-virus:Downloader.Win32.Firser
50.00%

F-Prot
W32/Morstar.C.gen, W32/Backdoor2.HTEZ
50.00%

ESET NOD32
Win32/FirseriaInstaller (variant)
25.00%

Dr.Web
Adware.Downware.1433
25.00%

The domain dl.s0ftohqimjjedf0jq.net has been seen to resolve to the following 11 IP addresses.

a23-67-243-27.deploy.static.akamaitechnologies.com
June 22, 2014

a23-67-243-75.deploy.static.akamaitechnologies.com
June 22, 2014

a23-67-243-83.deploy.static.akamaitechnologies.com
June 22, 2014

a23-67-243-98.deploy.static.akamaitechnologies.com
June 22, 2014

a23-67-243-59.deploy.static.akamaitechnologies.com
June 22, 2014

June 22, 2014

June 22, 2014

a23-67-243-91.deploy.static.akamaitechnologies.com
June 22, 2014

May 10, 2014

a23-67-243-50.deploy.static.akamaitechnologies.com
May 10, 2014

a23-67-243-18.deploy.static.akamaitechnologies.com
May 10, 2014

File downloads found at URLs served by dl.s0ftohqimjjedf0jq.net.

1 / 68      (Adware)
http://dl.s0ftohqimjjedf0jq.net/n/.../Matlab.exe  (7d40ba1841795a8e9b4a4203259c61eb)

11 / 68    (Adware)

24 / 68    (Adware)

11 / 68    (Adware)
http://dl.s0ftohqimjjedf0jq.net/n/.../VMP 0.2.1.383.exe  (9288f93ee5cf23c584df602e4e70c67a)

The following 337 files have been seen to comunicate with dl.s0ftohqimjjedf0jq.net in live environments.

 
Latest 20 of 338 files