downland.aabedo.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain downland.aabedo.com is registered by proxy through ENOM, INC. and was originally registered in March of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Thursday, March 13, 2014

Expires date:
Friday, March 13, 2015

Updated date:
Thursday, March 13, 2014

ASN:
AS16265 FIBERRING LeaseWeb B.V.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.PaymentsInteractiveSL.L, PUP.Tuguu.PaymentsInteractive.Bundler (M), PUP.Tuguu (M)
100.00%

Malwarebytes
PUP.Optional.DomaIQ
25.00%

K7 Gateway Antivirus
Trojan
25.00%

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
25.00%

Agnitum Outpost
PUA.DomaIQ
25.00%

Sophos
DomainIQ pay-per install
25.00%

VIPRE Antivirus
DomaIQ
25.00%

Avira AntiVirus
APPL/DomaIQ.Gen
25.00%

Jiangmin
Pack.Mal.AntiVM
25.00%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/MSIL.DomaIQ
25.00%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
25.00%

ESET NOD32
Win32/DomaIQ.BB (variant)
25.00%

IKARUS anti.virus
AdWare.DomaIQ
25.00%

AVG
DomaIQ_r.G
25.00%

Panda Antivirus
PUP/MultiToolbar.A
25.00%

The domain downland.aabedo.com has been seen to resolve to the following IP address.

March 20, 2014

File downloads found at URLs served by downland.aabedo.com.

1 / 68      (Adware)
http://downland.aabedo.com/.../flashplayer.exe  (437d6a104bb0778b528efb3c629a40f1)

1 / 68      (Adware)
http://downland.aabedo.com/.../flashplayer.exe  (e4777c577f09c75e26a873fed53e0255)

1 / 68      (Adware)
http://downland.aabedo.com/.../flashplayer.exe  (f44f0cc82f292d305fa47131fdc50b88)

20 / 68    (Adware)
http://downland.aabedo.com/.../flashplayer.exe  (d21fe430fab303bf59d90fb6603e9c0e)

URL:
http://downland.aabedo.com/

Title:
“LNMP一键安装包 by Licess”

Description:
“您已成功安装LNMP一键安装包!”

Web server:
nginx

Alexa:
Global rank:  986,969

Statistics are for the previous month (Alexa statistics are for entire aabedo.com).