download.lphant.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download.lphant.com is registered by proxy through GODADDY.COM, LLC and was originally registered in April of 2003. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Tel Aviv, Tel Aviv within Israel which resides on the RIPE Network Coordination Centre network.
Remove Malware from download.lphant.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Tel Aviv, Israel (IL)

Create date:
Wednesday, April 30, 2003

Expires date:
Saturday, April 30, 2016

Updated date:
Wednesday, April 15, 2015

ASN:
AS6461 MFNX MFN - Metromedia Fiber Network

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.BandooMedia.I, PUP.Optional.Installer.BandooMedia.V, PUP.Optional.BandooMedia.I, PUP.Optional.Installer.V, Win32.Generic.Bandoo.Installer.Meta
100.00%

Malwarebytes
PUP.Optional.Bandoo.A
36.36%

Dr.Web
Adware.Bandoo.13, Adware.Bandoo.12, Adware.Bandoo.242
27.27%

Bkav FE
W32.Clod7df.Trojan, W32.HfsAdware
18.18%

Trend Micro House Call
TROJ_GEN.F47V0210, Suspicious_GEN.F47V0330
18.18%

IKARUS anti.virus
PUA.Toolbar.SearchSuite
9.09%

K7 AntiVirus
Adware
9.09%

K7 Gateway Antivirus
Adware
9.09%

avast!
Win32:Adware-gen [Adw]
9.09%

NANO AntiVirus
Riskware.Win32.Bandoo.dgnlaz
9.09%

VIPRE Antivirus
Trojan.Win32.Generic
9.09%

Antiy Labs AVL
Trojan/Win32.TSGeneric
9.09%

AhnLab V3 Security
Win-PUP/SearchSuite
9.09%

ESET NOD32
Win32/Toolbar.SearchSuite potentially unwanted
9.09%

McAfee
Artemis!E868870C1FCC
9.09%

The domain download.lphant.com has been seen to resolve to the following IP address.

94.31.0.25.IPYX-076665-ZYO.above.net
December 28, 2013

File downloads found at URLs served by download.lphant.com.

2 / 68      (PUP)
http://download.lphant.com/LphantV7.exe  (lphantsetup-r126-n-bf.exe)

2 / 68      (PUP)
http://download.lphant.com/LphantV7.exe  (f8a5ba02066d7d760f89a9d660b6c36b)

1 / 68      (PUP)
http://download.lphant.com/LphantSetup.exe  (lphantsetup-r0-n-bc.exe)

1 / 68      (PUP)
http://download.lphant.com/LphantV7nl.exe  (3c693f3253f414861fbb41214a390385)

17 / 68    (PUP)

4 / 68      (PUP)
http://download.lphant.com/LphantV7.exe  (lphantsetup-r126-n-bf.exe)

4 / 68      (PUP)
http://download.lphant.com/LphantV7nl.exe  (lphantsetup-r126-n-bf.exe)

4 / 68      (PUP)
http://download.lphant.com/LphantV7es.exe  (lphantsetup-r126-n-bf.exe)

1 / 68      (PUP)
http://download.lphant.com/LphantV7.exe  (97504c49031c79481e8b17c8fad02076)

3 / 68      (PUP)
http://download.lphant.com/LphantSetup.exe  (lphantsetup-r161-n-bc_2.exe)

1 / 68      (PUP)
http://download.lphant.com/LphantV7.exe  (1544a3870317cb4c3cc1d9af2855983a)

2 / 68      (PUP)
http://download.lphant.com/LphantSetup.exe  (lphantsetup-r126-n-bf.exe)

1 / 68      (PUP)
http://download.lphant.com/LphantV7.exe  (c2470dd0320306802c91ad41cb88286b)

2 / 68      (PUP)
http://download.lphant.com/LphantV7.exe  (lphantsetup-r172-n-bc.exe)

The following 2 files have been seen to comunicate with download.lphant.com in live environments.

URL:
http://download.lphant.com/

Web server:
Apache

30 of 47 related domains

Remove Malware from download.lphant.com - Powered by Reason Core Security