download.garenatotal.com

Whois Privacy Protection Service, Inc.  (Proxy Registrant)

Domain Information

The domain download.garenatotal.com is registered by proxy through NAME.COM, INC. and was originally registered in January of 2013. Currently this domain has been known to host various forms of malware. The hosted servers are located in San Francisco, California within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
NAME.COM, INC.

Server location:
California, United States (US)

Create date:
Tuesday, January 29, 2013

Expires date:
Sunday, January 29, 2017

Updated date:
Friday, January 22, 2016

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Root domain:

Scanner detections:
Malware distribution  (64% detected)

Scan engine
Details
Detections

F-Prot
W32/NewMalware-LSU-based!Maximu, W32/Sality.gen2, W32/VB.AD.gen, W32/Sality.E.gen, W32/SuspPack.AA.gen
78.95%

avast!
Win32:Malware-gen, Win32:Sality, Win32:SaliCode, Win32:Kukacka, Win32:VB-OJQ [Wrm], Win32:Crypt-SJB [Trj]
78.95%

Norman
Suspicious_Gen4.GYYJW, Win32.Sality.3, Trojan.Generic.6753864, Trojan.Generic.8613015, Win32.Jeefo.B
73.68%

ESET NOD32
Win32/Sality.NBA virus, Win32/VB.OSK trojan, Win32/VB.QQC trojan
68.42%

Microsoft Security Essentials
Threat.Undefined
68.42%

Emsisoft Anti-Malware
Dropped:Trojan.Generic.11647061, Win32.Sality, Trojan.Generic.6753864, Trojan.Generic.8613015, Win32.Jeefo
63.16%

Dr.Web
Win32.Sector.30, Trojan.Siggen6.54687, Trojan.Siggen6.29778
57.89%

McAfee
Artemis!F50A4D077EE6, Virus.W32/Sality.gen.z, Virus.W32/Swisyn.ag
52.63%

Kaspersky
Trojan.Win32.Swisyn, Virus.Win32.Sality, Trojan-Dropper.Win32.VB
47.37%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4758034, Threat.4721115, Threat.4763461
36.84%

AVG
Generic11_c, Win32/Sality, Win32/Hidrag.A
36.84%

Qihoo 360 Security
Win32/RootKit.Rootkit.7e5, HEUR/QVM06.2.Malware.Gen
10.53%

Reason Heuristics
Threat.Win.Reputation.IMP
10.53%

Sophos
Mal/ZipMal-A, Virus 'Mal/Sality-D'
10.53%

F-Secure
Trojan.Generic.6753864, Win32.Sality.3
10.53%

The domain download.garenatotal.com has been seen to resolve to the following 6 IP addresses.

May 5, 2015

May 5, 2015

December 1, 2014

December 1, 2014

cf-173-245-61-6.cloudflare.com
June 9, 2014

cf-173-245-60-6.cloudflare.com
June 9, 2014

File downloads found at URLs served by download.garenatotal.com.

0 / 68
http://download.garenatotal.com/GarenaTotal.exe  (588d43f1dba1d29d0bf087ade482707b)

5 / 68      (Malware)
http://download.garenatotal.com/GarenaTotal.exe  (1b55759d6c0c3c6008c5c05c80eca94f)

5 / 68      (Malware)
http://download.garenatotal.com/GarenaTotal.exe  (f29727c40cb40f5a4e100ec28850795f)

9 / 68      (Infected)
http://download.garenatotal.com/GarenaTotal.exe  (53ef24de3e387eefcdff4a5094023de9)

7 / 68      (Infected)
http://download.garenatotal.com/GarenaTotal.exe  (324866c598cc1c9e2c3e9a205068348d)

11 / 68    (Infected)
http://download.garenatotal.com/GarenaTotal.exe  (e9698195e92cee8b63f2faafc95b2f1a)

7 / 68      (Malware)
http://download.garenatotal.com/GarenaTotal.exe  (d9e58fd28a35d099c77864b6c6910394)

9 / 68      (Malware)
http://download.garenatotal.com/GarenaTotal.exe  (fbf91ba109ce2c1a1db436959a5b0c46)

11 / 68    (Malware)
http://download.garenatotal.com/GarenaTotal.exe  (73f3c5af26f9ca0cafdbaa02fe853e26)

10 / 68    (Infected)
http://download.garenatotal.com/GarenaTotal.exe  (7a22ef56259a0797a48c5b8fc51b3ae1)

1 / 68      (Malware)
http://download.garenatotal.com/GarenaTotal.exe  (c847f2afbacfda0756690622537b8c1a)

7 / 68      (Infected)
http://download.garenatotal.com/GarenaTotal.exe  (5660c3048780d447dd783bf904e28fdc)

8 / 68      (Infected)
http://download.garenatotal.com/GarenaTotal.exe  (dcc7a0bff91cdbdd7aa311c2de0dd0c5)

9 / 68      (Infected)
http://download.garenatotal.com/GarenaTotal.exe  (3934584ac5e03f0bba52c556d442545a)

0 / 68
http://download.garenatotal.com/GarenaTotal.exe  (55336bb06d448d8255bcdb7b5d6bb2c8)

11 / 68    (Infected)
http://download.garenatotal.com/GarenaTotal.exe  (994c1a01ec971c257558e82e3f02bef1)

0 / 68
http://download.garenatotal.com/GarenaTotal.exe  (e9b6d7f0228f5649bf60d7c338ab6afd)

0 / 68
http://download.garenatotal.com/GarenaTotal.exe  (2b795233304e681f637c58bfa7395e6b)

0 / 68
http://download.garenatotal.com/GarenaTotal.exe  (45d7e84858a354014ed22388723226ee)

13 / 68    (Infected)
http://download.garenatotal.com/GarenaTotal.exe  (3ed031dec85228bb6f0cd8fa3b724e2d)

1 / 68
http://download.garenatotal.com/GarenaTotal.exe  (10e8a1eb177736e8f84b82c1c5da16fb)

0 / 68
http://download.garenatotal.com/GarenaTotal.exe  (564f11323263b5e6f16e27942914100c)

0 / 68
http://download.garenatotal.com/GarenaTotal.exe  (8b91b766d4ee4c76c10894cf934a8d6a)

28 / 68    (Malware)
http://download.garenatotal.com/GarenaTotal.exe  (efc07f71f59e9681cf361f5899c022c0)

URL:
http://download.garenatotal.com/

SSL certificate subject:
CN=sni37355.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx