download.expresdownload.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download.expresdownload.com is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Tel Aviv, Tel Aviv within Israel which resides on the RIPE Network Coordination Centre network.
Remove Malware from download.expresdownload.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Tel Aviv, Israel (IL)

Create date:
Wednesday, October 09, 2013

Expires date:
Monday, October 09, 2017

Updated date:
Wednesday, September 09, 2015

ASN:
AS6461 MFNX MFN - Metromedia Fiber Network

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.BandooMedia.V, PUP.Optional.Installer.W, PUP.Optional.Installer.V, PUP.Optional.Installer.EE, PUP.Bandoo.BandooMedia.Installer (M), Win32.Generic
100.00%

Malwarebytes
PUP.Optional.Bandoo
72.73%

ESET NOD32
Win32/iLivid (variant)
72.73%

Baidu Antivirus
Adware.Win32.iLivid, Adware.Win32.SearchSuite
72.73%

McAfee
Artemis!B6A829DFA975, Artemis!875998794E2E, Artemis!430BA1894F53, Artemis!F461DB6FE8FE, Artemis!7EFD1599C665, Artemis!7953344719D5, Artemis!919DBB95C7A3
63.64%

VIPRE Antivirus
iLivid, Threat.5059975, Trojan.Win32.Generic
63.64%

McAfee Web Gateway
Artemis!B6A829DFA975, Artemis!875998794E2E, BehavesLike.Win32.Downloader.tc
63.64%

AVG
MalSign.Generic
54.55%

Dr.Web
Adware.Bandoo.13, Adware.Bandoo.19, Adware.Bandoo.168
45.45%

IKARUS anti.virus
PUA.SearchSuite, PUA.iLivid
45.45%

Avira AntiVirus
APPL/Downloader.Gen
45.45%

Trend Micro House Call
TROJ_GEN.F47V0219, Suspicious_GEN.F47V0723, Suspicious_GEN.F47V0731, Suspicious_GEN.F47V1028
36.36%

Fortinet FortiGate
Riskware/ILivid, Riskware/SearchSuite
36.36%

Agnitum Outpost
PUA.Toolbar.SearchSuite
27.27%

Comodo Security
Application.Win32.iLivid.~A
18.18%

The domain download.expresdownload.com has been seen to resolve to the following IP address.

94.31.0.27.IPYX-076665-ZYO.above.net
May 23, 2014

File downloads found at URLs served by download.expresdownload.com.

17 / 68    (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

8 / 68      (PUP)

9 / 68      (PUP)
http://download.expresdownload.com/iLividSetup.exe  (لم يتم تأكيده 803792.crdownload)

18 / 68    (PUP)

9 / 68      (PUP)

9 / 68      (PUP)

14 / 68    (PUP)

15 / 68    (PUP)

9 / 68      (PUP)

The following 3 files have been seen to comunicate with download.expresdownload.com in live environments.

URL:
http://download.expresdownload.com/

Web server:
Apache

Remove Malware from download.expresdownload.com - Powered by Reason Core Security