download.di.downloadzinc.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download.di.downloadzinc.net is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Wednesday, October 8, 2014

Expires date:
Thursday, October 8, 2015

Updated date:
Wednesday, October 8, 2014

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Root domain:

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.QuickDownloader.H, PUP.Installer.SoftDownloads.M, PUP.Installer.Adlogica, PUP.Adlogica, PUP.Adlogica.QuickDownloader.Bundler (M), PUP.Adlogica.SoftDownloads.Bundler (M), PUP.Adlogica.SoftDown.Bundler (M)
100.00%

Dr.Web
Trojan.Packed.28678, Trojan.InstallCore.7
41.67%

VIPRE Antivirus
Threat.4786018, Threat.4150696, Threat.4823950
41.67%

K7 AntiVirus
Unwanted-Program , Trojan
41.67%

Agnitum Outpost
PUA.OutBrowse, PUA.InstallCore
41.67%

Avira AntiVirus
APPL/Downloader.Gen, ADWARE/InstallCore.Gen7
41.67%

AVG
Generic, Adware InstallCore
41.67%

ESET NOD32
Win32/InstallCore.OZ potentially unwanted application, Win32/OutBrowse.AY potentially unwanted application
41.67%

F-Prot
W32/InstallCore.AC.gen, W32/InstallCore.AG.gen
33.33%

Sophos
PUA 'Install Core Click run software', PUA 'OutBrowse' (of type Adware)
33.33%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen, Hoax.PornoAsset
25.00%

NANO AntiVirus
Trojan.Text.Drop.dhqasj, Trojan.Win32.OutBrowse.dgnlgr
25.00%

Clam AntiVirus
Win.Trojan.Installcore-292
25.00%

Comodo Security
Application.Win32.InstallCore.DWQ, UnclassifiedMalware
25.00%

McAfee
Adware-OutBrowse.b
16.67%

The domain download.di.downloadzinc.net has been seen to resolve to the following 4 IP addresses.

July 16, 2015

July 16, 2015

October 20, 2014

October 20, 2014

File downloads found at URLs served by download.di.downloadzinc.net.

URL:
http://download.di.downloadzinc.net/

Title:
“DownloadzInc - DownloadInfo”

Web server:
cloudflare-nginx (PHP/5.5.9-1ubuntu4)