download.theappsrvr.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download.theappsrvr.com is registered by proxy through GODADDY.COM, LLC and was originally registered in January of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Remove Malware from download.theappsrvr.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Monday, January 04, 2016

Expires date:
Wednesday, January 04, 2017

Updated date:
Saturday, January 23, 2016

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.SavingsApps.F, PUP.Installer.50OnRed, PUP.50OnRed.SavingsApps.Installer (M), PUP.Air Software.AirSoftware.Bundler (M)
100.00%

SUPERAntiSpyware
Trojan.Agent/Gen-FakeAV, Trojan.Agent/Gen-StartPage, Adware.AirAdInstaller
29.17%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, AdWare.AirAdInstaller
25.00%

Trend Micro House Call
HV_ZYX_.5CACB583, HV_ZYX_.97F06626, Suspici.DC06088C
16.67%

Qihoo 360 Security
Malware.QVM06.Gen, Malware.QVM01.Gen
12.50%

Avira AntiVirus
TR/Dropper.Gen, Adware/AgentCV.A.6255
8.33%

Rising Antivirus
PE:Trojan.Win32.Generic.173D615C!389898588, PE:PUF.Airinstall!1.9C4C
8.33%

Quick Heal
(Suspicious) - DNAScan
4.17%

Malwarebytes
PUP.Optional.AirAdInstaller
4.17%

K7 Gateway Antivirus
Unwanted-Program
4.17%

avast!
Win32:Adware-gen [Adw]
4.17%

Agnitum Outpost
PUA.AirAdInstaller
4.17%

Comodo Security
Application.Win32.AirAdInstaller.B
4.17%

Dr.Web
Trojan.SMSSend.4953
4.17%

VIPRE Antivirus
Threat.4150696
4.17%

The domain download.theappsrvr.com has been seen to resolve to the following 4 IP addresses.

February 8, 2016

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
January 28, 2016

ip-50-63-202-56.ip.secureserver.net
October 26, 2015

May 1, 2014

File downloads found at URLs served by download.theappsrvr.com.

The following 7 files have been seen to comunicate with download.theappsrvr.com in live environments.

URL:
http://download.theappsrvr.com/

Title:
“Loading”

Web server:
nginx/1.8.0

Remove Malware from download.theappsrvr.com - Powered by Reason Core Security