downclaralabs.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain downclaralabs.com is registered by proxy through ENOM, INC. and was originally registered in February of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in San Jose, California within the United States which resides on the CDNetworks Inc. network.
Registrar:
ENOM, INC.

Server location:
California, United States (US)

Create date:
Wednesday, February 18, 2015

Expires date:
Thursday, February 18, 2016

Updated date:
Wednesday, February 18, 2015

ASN:
AS36408 CDNETWORKSUS-02 CDNetworks Inc.

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.CLARALABSOFTWARE.Installer (M), PUP.CLARALAB.Installer (M)
100.00%

Malwarebytes
PUP.Optional.Clara.A
50.00%

Trend Micro House Call
Suspicious_GEN.F47V0221
50.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
50.00%

F-Secure
Gen:Variant.Adware.Symmi.49687
50.00%

Qihoo 360 Security
Malware.QVM20.Gen
50.00%

Dr.Web
Adware.Searcher.2787
50.00%

Panda Antivirus
PUP/Clara
50.00%

IKARUS anti.virus
AdWare.Searcher
50.00%

The domain downclaralabs.com has been seen to resolve to the following 4 IP addresses.

February 13, 2016

February 13, 2016

January 31, 2016

January 31, 2016

File downloads found at URLs served by downclaralabs.com.

1 / 68      (PUP)

1 / 68      (PUP)

9 / 68      (PUP)

9 / 68      (PUP)

The following 27 files have been seen to comunicate with downclaralabs.com in live environments.

 
Latest 20 of 80 files

URL:
http://downclaralabs.com/

Web server:
PWS/8.1.20.25