download2.faceoffmax.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download2.faceoffmax.com is registered by proxy through GODADDY.COM, LLC and was originally registered in July of 2009. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the Linode network.
Registrar:
GODADDY.COM, LLC

Server location:
Texas, United States (US)

Create date:
Monday, July 13, 2009

Expires date:
Thursday, July 13, 2017

Updated date:
Tuesday, April 19, 2016

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.

Root domain:

Scanner detections:
Detections  (84% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.U, PUP.Optional.Installer.P, PUP.CoolwareMax.FaceOffMax (M)
69.23%

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant), Win32/Bundled.Toolbar.Ask.G potentially unsafe (variant)
65.38%

K7 Gateway Antivirus
Unwanted-Program
34.62%

K7 AntiVirus
Unwanted-Program
34.62%

Antiy Labs AVL
Trojan[Backdoor]/Win32.Sinowal
34.62%

Malwarebytes
PUP.Optional.APNToolBar.A
30.77%

NANO AntiVirus
Trojan.Win32.Bundled.cymxsf
23.08%

Dr.Web
Adware.Toolbar.332, Program.Unwanted.485, Trojan.Inject1.64015
19.23%

Trend Micro House Call
Suspicious_GEN.F47V0620, Suspicious_GEN.F47V1209, Suspicious_GEN.F47V0107
11.54%

IKARUS anti.virus
PUA.Offer
11.54%

Zillya! Antivirus
Worm.Vobfus.Win32.193080
3.85%

Quick Heal
PUA.Askcom.Gen
3.85%

Microsoft Security Essentials
Threat.Undefined
3.85%

avast!
Win32:Delf-TJJ [Trj]
3.85%

ESET NOD32
Win32/Delf.QJF trojan
3.85%

The domain download2.faceoffmax.com has been seen to resolve to the following IP address.

li454-217.members.linode.com
April 16, 2014

File downloads found at URLs served by download2.faceoffmax.com.

6 / 68      (PUP)

4 / 68      (PUP)

0 / 68

4 / 68      (PUP)

0 / 68

0 / 68

1 / 68      (Malware)

1 / 68      (Malware)

5 / 68      (PUP)

2 / 68      (PUP)

5 / 68      (PUP)

1 / 68      (Malware)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (Malware)

1 / 68      (Malware)

3 / 68      (PUP)

1 / 68      (Malware)

5 / 68      (PUP)

10 / 68    (Malware)

1 / 68      (Malware)

6 / 68      (PUP)

3 / 68      (PUP)

6 / 68      (PUP)

The following file have been seen to comunicate with download2.faceoffmax.com in live environments.

URL:
http://download2.faceoffmax.com/

Title:
“Kloxo Control Panel”

Web server:
Apache/2.2.21 (CentOS) (PHP/5.3.8)

Facebook:
Shares:  2

Statistics are for the previous month.