downloads.gufile.com

Only contact by email, all postal mail will be rejected  (Proxy Registrant)

Domain Information

The domain downloads.gufile.com is registered by proxy through SOLUCIONES CORPORATIVAS IP, SL and was originally registered in November of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
SOLUCIONES CORPORATIVAS IP, SL

Server location:
Oregon, United States (US)

Create date:
Monday, November 12, 2012

Expires date:
Saturday, November 12, 2016

Updated date:
Thursday, October 29, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.TuguuSL.M, PUP.TuguuSL.V, PUP.TuguuSL.R, PUP.SambamediaSL.V, PUP.SambamediaSL.L, PUP.TUGUUSL.F, PUP.TuguuSL.J, PUP.SambamediaSL.I, PUP.TUGUUSL.V, PUP.TuguuSL.F, PUP.TuguuSL.G, PUP.Bundler.Tuguu, Threat.Tuguu.Bundler, PUP.Tuguu.Bundler (M), PUP.Softpulse.Sambamed.Bundler (M), PUP.Tuguu (M)
96.00%

VIPRE Antivirus
Threat.4783235, Threat.4150696, Trojan.Win32.Generic, DomaIQ
34.00%

avast!
DomaIQ-CC [PUP], PUP-gen [PUP], Win32:Malware-gen, Win32:SoftPulse-U [PUP], Win32:Adware-BQR [Adw], DomaIQ-CO [PUP], Win32:DomaIQ-BS [PUP]
34.00%

McAfee
Adware-DomaIQ!C896CDE92947, Adware-DomaIQ!87EAB94F6E66, CryptDomaIQ, Socrydo, SoftPulse, PUP-FJP!62C17A287E12, RDN/Generic.bfr!et
34.00%

Avira AntiVirus
APPL/DomaIQ.Gen, TR/Dropper.Gen, APPL/Bundler.DomaIQ.C.1, APPL/Softpulse.Gen8, TR/Inject.owlpanom, APPL/DomaIQ.cpb, APPL/DomaIQ.beor
34.00%

AVG
Adware DomaIQ.BB, Adware Skodna.Bundle_r.Y, Adware DomaIQ_r.K, Generic, Trojan horse Downloader.Generic13.CHXB.dropper, Adware DomaIQ.DQ
34.00%

Malwarebytes
PUP.Optional.DomalQ, PUP.Optional.BundleInstaller.A, PUP.Optional.DomaIQ, PUP.Optional.InstallRex, PUP.Optional.Dropper.BL
32.00%

K7 Gateway Antivirus
Unwanted-Program , Trojan
32.00%

K7 AntiVirus
Unwanted-Program , Trojan
32.00%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious.H, Heuristic.LooksLike.Win32.Suspicious.I, Socrydo, CryptDomaIQ, BehavesLike.Win32.MPlug.tc
32.00%

Sophos
DomainIQ pay-per install, SoftPulse, Troj/MSIL-MD, Generic PUA PF, PUA 'DomainIQ pay-per install', Virus 'Troj/MSIL-MD'
32.00%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/Win32.Lollipop, GrayWare[AdWare:not-a-virus]/MSIL.DomaIQ, Trojan[:HEUR]/Win32.AGeneric, Trojan/Win32.TGeneric
32.00%

MicroWorld eScan
Dropped:Adware.Generic.926650, Gen:Variant.Application.Bundler.DomaIQ.3, Gen:Variant.Adware.Kazy.374465, Gen:Variant.Adware.Strictor.58754
30.00%

Kaspersky
not-a-virus:AdWare.Win32.Lollipop, not-a-virus:AdWare.MSIL.DomaIQ, not-a-virus:HEUR:AdWare.MSIL.DomaIQ
30.00%

Bitdefender
Dropped:Adware.Generic.926650, Gen:Variant.Application.Bundler.DomaIQ.3, Gen:Variant.Adware.Kazy.374465, Gen:Variant.Adware.Strictor.58754
30.00%

The domain downloads.gufile.com has been seen to resolve to the following 8 IP addresses.

ec2-52-10-139-14.us-west-2.compute.amazonaws.com
May 21, 2015

ec2-52-10-43-205.us-west-2.compute.amazonaws.com
May 21, 2015

ec2-54-187-111-79.us-west-2.compute.amazonaws.com
August 12, 2014

ec2-54-218-87-136.us-west-2.compute.amazonaws.com
August 12, 2014

ec2-54-187-72-39.us-west-2.compute.amazonaws.com
June 5, 2014

ec2-54-201-20-36.us-west-2.compute.amazonaws.com
May 23, 2014

ec2-54-201-62-44.us-west-2.compute.amazonaws.com
March 6, 2014

ec2-54-218-48-102.us-west-2.compute.amazonaws.com
February 27, 2014

File downloads found at URLs served by downloads.gufile.com.

1 / 68      (Adware)
http://downloads.gufile.com/.../microsoft-office-2010.exe  (96a9ab6a89616179f12541993880faa1)

1 / 68      (Adware)
http://downloads.gufile.com/.../itunes.exe  (da73668b46ee8762b8a7acbb7b8901d9)

1 / 68      (Adware)

1 / 68      (Adware)
http://downloads.gufile.com/.../quicktime.exe  (e4f6bdac66cc13157209d70883547ed8)

1 / 68      (Adware)

1 / 68      (Adware)
http://downloads.gufile.com/.../avast.exe  (f81f5abacee3cf6ba41f0788290bc760)

1 / 68      (Adware)
http://downloads.gufile.com/.../microsoft-publisher.exe  (167ad509a531f3879347b1cf4dceca63)

2 / 68      (false positives)

1 / 68      (Adware)
http://downloads.gufile.com/.../hjsplit.exe  (2cd8f065f1aa0eacc60735f4bf75a552)

1 / 68      (Adware)
http://downloads.gufile.com/.../google-chrome-dev.exe  (c41bac9e11d7cf605d17f5e25b6b0be0)

1 / 68      (Adware)
http://downloads.gufile.com/.../imvu.exe  (e3678ae5263c3b8214aabe0bca540cfc)

1 / 68      (Adware)

24 / 68    (PUP)
http://downloads.gufile.com/.../Microsoft-Silverlight.exe  (48893c6330371cd75c3c27dcc45b141f)

10 / 68    (Adware)
http://downloads.gufile.com/.../whatsapp.exe  (c67fa4dbc065c4ee8a2f2db9169b8218)

33 / 68    (Adware)
http://downloads.gufile.com/.../microsoft-office-2013.exe  (4c9d4bf0ae401848ed0ba81c9abe1bdd)

18 / 68    (Adware)
http://downloads.gufile.com/.../itunes32_64.exe  (87ba642a37ae47fc31ce65de099d56e7)

36 / 68    (Adware)
http://downloads.gufile.com/.../free-yahtzee-game.exe  (552b604bccda10d8386aaa92b82b015b)

The following 9 files have been seen to comunicate with downloads.gufile.com in live environments.