downland.acdebo.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain downland.acdebo.com is registered by proxy through ENOM, INC. and was originally registered in March of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Friday, March 07, 2014

Expires date:
Saturday, March 07, 2015

Updated date:
Friday, March 07, 2014

ASN:
AS16265 FIBERRING LeaseWeb B.V.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.PaymentsInteractiveSL.L, PUP.Tuguu.PaymentsInteractive.Bundler (M), PUP.Tuguu.Payments.Bundler (M)
100.00%

MicroWorld eScan
Gen:Variant.Application.Bundler.DomaIQ.3
20.00%

McAfee
PUP-FJP!6ED9A5CF8738
20.00%

Malwarebytes
PUP.Optional.BundleInstaller.A
20.00%

Zillya! Antivirus
Adware.DomaIQ.Win32.178
20.00%

K7 Gateway Antivirus
Unwanted-Program
20.00%

K7 AntiVirus
Unwanted-Program
20.00%

NANO AntiVirus
Riskware.Win32.Downware.cvxwqj
20.00%

avast!
Win32:DomaIQ-BM [PUP]
20.00%

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
20.00%

Bitdefender
Gen:Variant.Application.Bundler.DomaIQ.3
20.00%

Agnitum Outpost
PUA.DomaIQ
20.00%

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.DomaIQ.3
20.00%

Sophos
DomainIQ pay-per install
20.00%

Comodo Security
Application.Win32.DomaIQ.PUT
20.00%

The domain downland.acdebo.com has been seen to resolve to the following IP address.

May 7, 2014

File downloads found at URLs served by downland.acdebo.com.

1 / 68      (Adware)
http://downland.acdebo.com/.../flashplayer.exe  (c8679772f5208f43a3f0d518ed37968f)

1 / 68      (Adware)
http://downland.acdebo.com/.../flashplayer.exe  (e7788f29f0a2db777471797531ac2112)

1 / 68      (Adware)
http://downland.acdebo.com/.../flashplayer.exe  (5cb99f561c2bb4640a37947bc4f035b4)

1 / 68      (Adware)
http://downland.acdebo.com/.../flashplayer.exe  (f78733f2b6094e6760bb20463474b089)

31 / 68    (Adware)
http://downland.acdebo.com/.../flashplayer.exe  (c6d4109fa90fb78c6d605d45fa61a425)