download.expressdownload.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download.expressdownload.net is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Tel Aviv, Tel Aviv within Israel which resides on the RIPE Network Coordination Centre network.
Remove Malware from download.expressdownload.net - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Tel Aviv, Israel (IL)

Create date:
Tuesday, October 08, 2013

Expires date:
Sunday, October 08, 2017

Updated date:
Wednesday, September 09, 2015

ASN:
AS6461 MFNX MFN - Metromedia Fiber Network

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.BandooMedia.V, PUP.Optional.Installer.W, PUP.Optional.Installer.V, PUP.Installer.BandooMedia.V, PUP.Installer.BandooMedia.W, PUP.Bandoo.Installer, Win32.Generic.BandooMedia.Installer.Meta, PUP.Bandoo.BandooMedia.Installer (M)
95.83%

Malwarebytes
PUP.Optional.Bandoo
79.17%

Dr.Web
Adware.Bandoo.13, Trojan.Damaged.1, Adware.Bandoo.19, Adware.Bandoo.168, Adware.Bandoo.194
62.50%

ESET NOD32
Win32/Toolbar.SearchSuite (variant), Win32/iLivid (variant)
62.50%

AVG
MalSign.Generic, Adware Generic_r.VQ
58.33%

VIPRE Antivirus
Trojan.Win32.Generic, iLivid, Threat.5059975, Threat.4150696
58.33%

Baidu Antivirus
Adware.Win32.iLivid
58.33%

Avira AntiVirus
TR/Trash.Gen, APPL/Downloader.Gen, APPL/Bandoo.lpqsa, Adware/SeaSuite.inze, PUA/iLivid.Gen
45.83%

McAfee Web Gateway
Artemis!9556A78BB7AC, Artemis!C242B5A5B592, Artemis!B6A829DFA975, Artemis!875998794E2E, Artemis!Trojan, BehavesLike.Win32.Downloader.tc, BehavesLike.Win32.Multiplug.mh
45.83%

McAfee
Artemis!9556A78BB7AC, Artemis!C242B5A5B592, Artemis!B6A829DFA975, Artemis!875998794E2E, Artemis!430BA1894F53, Artemis!F461DB6FE8FE, Artemis!D0475DE2AB77, Artemis!7EFD1599C665, Artemis!9386EDF85849
37.50%

Trend Micro House Call
TROJ_GEN.F47V0102, TROJ_GEN.F47V0219, TROJ_GEN.F47V0605, Suspicious_GEN.F47V0617, Suspicious_GEN.F47V0717, Suspicious_GEN.F47V0723
29.17%

Fortinet FortiGate
Riskware/ILivid, Riskware/Win64_SearchSuite, Riskware/SearchSuite
29.17%

Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite, not-a-virus:WebToolbar.Win32.SearchSuite
29.17%

IKARUS anti.virus
PUA.Bandoo, PUA.SearchSuite, PUA.iLivid
29.17%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
20.83%

The domain download.expressdownload.net has been seen to resolve to the following IP address.

94.31.0.27.IPYX-076665-ZYO.above.net
December 26, 2013

File downloads found at URLs served by download.expressdownload.net.

1 / 68      (PUP)

19 / 68    (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

2 / 68

20 / 68    (PUP)

13 / 68    (PUP)

10 / 68    (PUP)

9 / 68      (PUP)

12 / 68    (PUP)

11 / 68    (PUP)

9 / 68      (PUP)

14 / 68    (PUP)

9 / 68      (PUP)

17 / 68    (PUP)

9 / 68      (PUP)

8 / 68      (PUP)

14 / 68    (PUP)

4 / 68      (Malware)

15 / 68    (PUP)

0 / 68

13 / 68    (PUP)

9 / 68      (PUP)

5 / 68      (PUP)

6 / 68      (PUP)

The following 3 files have been seen to comunicate with download.expressdownload.net in live environments.

URL:
http://download.expressdownload.net/

Web server:
Apache

Facebook:
Shares:  1

Statistics are for the previous month.

Remove Malware from download.expressdownload.net - Powered by Reason Core Security