download.bandooo.com

Milen Radumilo

Domain Information

The domain download.bandooo.com registered by Milen Radumilo was initially registered in December of 2015 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Tel Aviv, Tel Aviv within Israel which resides on the RIPE Network Coordination Centre network.
Remove Malware from download.bandooo.com - Powered by Reason Core Security
Registrar:
TUCOWS DOMAINS INC.

Server location:
Tel Aviv, Israel (IL)

Create date:
Thursday, December 31, 2015

Expires date:
Saturday, December 31, 2016

Updated date:
Thursday, December 31, 2015

ASN:
AS6461 MFNX MFN - Metromedia Fiber Network

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Dr.Web
Adware.Bandoo.15, Adware.Bandoo.280, Adware.Bandoo.15
100.00%

Reason Heuristics
PUP.Optional.Installer.I, Win32.Generic
100.00%

MicroWorld eScan
Win32/Toolbar.SearchSuite
50.00%

Emsisoft Anti-Malware
Riskware.Win32.Toolbar.SearchSuite.AMN
50.00%

ESET NOD32
Win32/Toolbar.SearchSuite potentially unwanted application
50.00%

Bkav FE
W32.HfsAdware
50.00%

VIPRE Antivirus
Trojan.Win32.Generic
50.00%

Trend Micro House Call
HV_ZYX_BK0846DB.TOMC
50.00%

Baidu Antivirus
PUA.Win32.Toolbar.SearchSuite
50.00%

AVG
Bandoo
50.00%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
50.00%

NANO AntiVirus
Trojan.Win32.Bandoo.bbfacc
50.00%

avast!
Adware-gen [Adw]
50.00%

McAfee Web Gateway
BehavesLike.Win32.Suspicious.tc
50.00%

SUPERAntiSpyware
PUP.Bandoo/Variant
50.00%

The domain download.bandooo.com has been seen to resolve to the following 2 IP addresses.

February 1, 2016

94.31.0.25.IPYX-076665-ZYO.above.net
April 6, 2014

File downloads found at URLs served by download.bandooo.com.

16 / 68    (PUP)
http://download.bandooo.com/o/5/r/.../BandooV8.exe  (508954edf90f11e77d108d394c3a3bdc)

2 / 68      (PUP)
http://download.bandooo.com/o/2/r/.../BandooV8.exe  (d3afeea0c8fc90ef0b215e352bd99f45)

2 / 68      (PUP)
http://download.bandooo.com/o/2/r/.../BandooV8.exe  (d3afeea0c8fc90ef0b215e352bd99f45)

The following 2 files have been seen to comunicate with download.bandooo.com in live environments.

URL:
http://download.bandooo.com/

Google Analytics:
UA-48689684

Title:
“bandooo.com”

Web server:
nginx

30 of 247 related domains

Remove Malware from download.bandooo.com - Powered by Reason Core Security