downland.acobeo.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain downland.acobeo.com is registered by proxy through ENOM, INC. and was originally registered in February of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Siauliai, Siauliu Apskritis within Lithuania which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Siauliu Apskritis, Lithuania (LT)

Create date:
Tuesday, February 25, 2014

Expires date:
Wednesday, February 25, 2015

Updated date:
Tuesday, February 25, 2014

ASN:
AS61272 IST-AS Informacines sistemos ir technologijos, UAB

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Awimba.L, PUP.Tuguu.PaymentsInteractive.Bundler (M), PUP.Tuguu.Payments.Bundler (M)
100.00%

McAfee
Adware-DomaIQ!F6CB534A58DC
25.00%

Malwarebytes
PUP.Optional.BundleInstaller.A
25.00%

K7 AntiVirus
Trojan
25.00%

K7 Gateway Antivirus
Trojan
25.00%

NANO AntiVirus
Trojan.Win32.DomaIQ.ctadmg
25.00%

avast!
Win32:DomaIQ-BF [PUP]
25.00%

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
25.00%

Comodo Security
Application.Win32.DomaIQ.URT
25.00%

Dr.Web
Trojan.DownLoader9.21779
25.00%

VIPRE Antivirus
DomaIQ
25.00%

Avira AntiVirus
APPL/DomaIQ.Gen
25.00%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious.H
25.00%

Sophos
Generic PUA HJ
25.00%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/MSIL.DomaIQ
25.00%

The domain downland.acobeo.com has been seen to resolve to the following IP address.

hst-188-51-25-185.ist.lt
March 3, 2014

File downloads found at URLs served by downland.acobeo.com.

1 / 68      (Adware)
http://downland.acobeo.com/.../flashplayer.exe  (8fce4ea5a8eb93c6d55e52ab7f0c0238)

1 / 68      (Adware)
http://downland.acobeo.com/.../flashplayer.exe  (08588d5c450799378fad35ac8a40948a)

1 / 68      (Adware)
http://downland.acobeo.com/.../flashplayer.exe  (2ffb5b1c45633840566007b12bc5e4e4)

20 / 68    (Adware)
http://downland.acobeo.com/.../flashplayer.exe  (899426df3beaebc173033410d43ac94a)

URL:
http://downland.acobeo.com/

Web server:
nginx

Alexa:
Global rank:  1,010,987

Statistics are for the previous month (Alexa statistics are for entire acobeo.com).