down2.morningsunsoft.com

Whois Privacy Protection Service, Inc.  (Proxy Registrant)

Domain Information

The domain down2.morningsunsoft.com is registered by proxy through NAME.COM, INC. and was originally registered in January of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Cedar Knolls, New Jersey within the United States which resides on the Linode network.
Registrar:
NAME.COM, INC.

Server location:
New Jersey, United States (US)

Create date:
Wednesday, January 23, 2013

Expires date:
Monday, January 23, 2017

Updated date:
Tuesday, December 2, 2014

ASN:
AS8001 NET-ACCESS-CORP - Net Access Corporation

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Trend Micro House Call
Suspicious_GEN.F47V0308
100.00%

Dr.Web
Adware.OpenCandy.115
100.00%

ESET NOD32
Win32/OpenCandy.C potentially unsafe application
100.00%

AVG
OpenCandy
100.00%

G Data
Win32.Adware.OpenCandy
100.00%

The domain down2.morningsunsoft.com has been seen to resolve to the following IP address.

li127-170.members.linode.com
August 28, 2015

File downloads found at URLs served by down2.morningsunsoft.com.

5 / 68      (PUP)
http://down2.morningsunsoft.com/MC_Setup.exe  (90b0339d270af8999e27f25b91c454a7)

The following 29 files have been seen to comunicate with down2.morningsunsoft.com in live environments.

 
Latest 20 of 30 files

URL:
http://down2.morningsunsoft.com/

Web server:
Apache/2.2.22 (Debian)