downland.aboede.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain downland.aboede.com is registered by proxy through ENOM, INC. and was originally registered in February of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the RIPE Network Coordination Centre network.
Remove Malware from downland.aboede.com - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Wednesday, February 26, 2014

Expires date:
Thursday, February 26, 2015

Updated date:
Wednesday, February 26, 2014

ASN:
AS16265 FIBERRING LeaseWeb B.V.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.PaymentsInteractiveSL.L, PUP.Solimba.EilioDevelopmentssl.Installer (M)
100.00%

Malwarebytes
PUP.Optional.DomalQ, .PUP.Optional.Solimba
100.00%

K7 Gateway Antivirus
Unwanted-Program
100.00%

Agnitum Outpost
PUA.DomaIQ, PUA.Downloader
100.00%

avast!
Win32:PUP-gen [PUP], Win32:Solimba-M [PUP]
100.00%

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ, not-a-virus:Downloader.Win32.Morstar
100.00%

Sophos
Troj/MSIL-MD, PUA.Solimba Installer
100.00%

Dr.Web
Trojan.DownLoader9.33391, Trojan.DownLoader11.24441
100.00%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4782980
100.00%

Avira AntiVirus
APPL/DomaIQ.Gen, APPL/Firseria.Gen8
100.00%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/MSIL.DomaIQ, Trojan[Downloader:not-a-virus]/Win32.Morstar.as
100.00%

G Data
Win32.Application.DomalQ, Gen:Variant.Application.Bundler.Kazy.132995
100.00%

Vba32 AntiVirus
BScope.Downware.DomaIQ, Downware.Morstar
100.00%

IKARUS anti.virus
Virus.Win32.Dropper, PUA.MSIL.Solimba
100.00%

AVG
DomaIQ.R, Adware BundleApp_r
100.00%

The domain downland.aboede.com has been seen to resolve to the following IP address.

March 27, 2014

File downloads found at URLs served by downland.aboede.com.

31 / 68    (Adware)
http://downland.aboede.com/.../flashplayer.exe  (2958ab68ff2da8229367c21795e8be76)

19 / 68    (Adware)
http://downland.aboede.com/.../flashplayer.exe  (977812100e857617d42bbb019c0b3277)

URL:
http://downland.aboede.com/

Title:
“LNMP一键安装包 by Licess”

Description:
“您已成功安装LNMP一键安装包!”

Web server:
nginx

Facebook:
Shares:  1

Alexa:
Global rank:  241,760
Backlinks:  3

Statistics are for the previous month (Alexa statistics are for entire aboede.com).

Remove Malware from downland.aboede.com - Powered by Reason Core Security