download.lphant.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download.lphant.com is registered by proxy through GODADDY.COM, LLC and was originally registered in April of 2003. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Tel Aviv, Tel Aviv within Israel which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Tel Aviv, Israel (IL)

Create date:
Wednesday, April 30, 2003

Expires date:
Sunday, April 30, 2017

Updated date:
Monday, March 14, 2016

ASN:
AS6461 MFNX MFN - Metromedia Fiber Network

Root domain:

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.BandooMedia.I, PUP.Optional.Installer.BandooMedia.V, PUP.Optional.BandooMedia.I, PUP.Optional.Installer.V, PUP.Optional.Installer.M, Win32.Generic.Bandoo.Installer.Meta
100.00%

Malwarebytes
PUP.Optional.Bandoo.A
37.50%

Dr.Web
Adware.Bandoo.13, Adware.Bandoo.12, Adware.Bandoo.167, Adware.Bandoo.242
25.00%

Trend Micro House Call
TROJ_GEN.F47V0210, Suspicious_GEN.F47V1114, Suspicious_GEN.F47V1118, Suspicious_GEN.F47V1127, Suspicious_GEN.F47V0217, Suspicious_GEN.F47V0330
25.00%

McAfee
Artemis!AEE67EE7DC30, Artemis!F35FAAF8D687, Artemis!F1DC1BE95422, Artemis!3CCA5D7D2DF8, Artemis!E868870C1FCC
20.83%

AVG
Generic
20.83%

McAfee Web Gateway
Artemis
16.67%

Baidu Antivirus
Adware.Win32.SearchSuite
16.67%

Clam AntiVirus
Win.Adware.Searchsuite-3
12.50%

Avira AntiVirus
Adware/AgentCV.A.8235, Adware/AgentCV.A.8556, Adware/AgentCV.A.10197
12.50%

Bkav FE
W32.Clod7df.Trojan, W32.HfsAdware
8.33%

K7 AntiVirus
Trojan , Adware
8.33%

K7 Gateway Antivirus
Trojan , Adware
8.33%

avast!
Win32:Adware-gen [Adw]
8.33%

NANO AntiVirus
Riskware.Win32.Bandoo.dmntaq, Riskware.Win32.Bandoo.dgnlaz
8.33%

The domain download.lphant.com has been seen to resolve to the following IP address.

94.31.0.25.IPYX-076665-ZYO.above.net
December 28, 2013

File downloads found at URLs served by download.lphant.com.

7 / 68      (PUP)
http://download.lphant.com/LphantSetup.exe  (lphantsetup-r184-n-bc.exe)

1 / 68      (PUP)
http://download.lphant.com/LphantV7es.exe  (f7c7ad64ff59eab82f3b62b132604e0c)

2 / 68      (PUP)
http://download.lphant.com/LphantV7nl.exe  (lphantsetup-r126-n-bc.exe)

1 / 68      (PUP)
http://download.lphant.com/LphantV8.exe  (lphantsetup-r0-n-bc.exe)

0 / 68
http://download.lphant.com/LphantV7.exe  (lphantsetup-r169-n-bc.exe)

1 / 68      (PUP)

1 / 68      (PUP)
http://download.lphant.com/LphantV7it.exe  (d51b5e9f4fa15c77450ee4a65b589387)

The following 15 files have been seen to comunicate with download.lphant.com in live environments.

URL:
http://download.lphant.com/

Web server:
Apache