downloads.gufile.com

Only contact by email, all postal mail will be rejected  (Proxy Registrant)

Domain Information

The domain downloads.gufile.com is registered by proxy through SOLUCIONES CORPORATIVAS IP, SL and was originally registered in November of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Remove Malware from downloads.gufile.com - Powered by Reason Core Security
Registrar:
SOLUCIONES CORPORATIVAS IP, SL

Server location:
Oregon, United States (US)

Create date:
Monday, November 12, 2012

Expires date:
Saturday, November 12, 2016

Updated date:
Thursday, October 29, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (97% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.TuguuSL.G, PUP.TuguuSL.P, PUP.TUGUUSL.T, PUP.TUGUUSL.G, PUP.TuguuSL.X, PUP.TuguuSL.T, PUP.TuguuSL.L, PUP.TuguuSL.M, PUP.TuguuSL.V, PUP.TuguuSL.R, PUP.SambamediaSL.V, PUP.SambamediaSL.L, PUP.TUGUUSL.F, PUP.TuguuSL.J, PUP.TUGUUSL.V, PUP.TuguuSL.F, PUP.Bundler.Tuguu, Threat.Tuguu.Bundler, PUP.Tuguu.Bundler (M)
97.22%

VIPRE Antivirus
DomaIQ, Trojan.Win32.Generic, Threat.4783235, Threat.4150696
66.67%

Avira AntiVirus
APPL/DomaIQ.Gen, APPL/DomaIQ.A.10, TR/Dropper.Gen, APPL/Bundler.DomaIQ.C.1, APPL/Softpulse.Gen8, TR/Inject.owlpanom, APPL/DomaIQ.cpb
66.67%

AVG
DomaIQ.W, DomaIQ_r.G, Adware DomaIQ.BB, Adware Skodna.Bundle_r.Y, Adware DomaIQ_r.K, Generic, Trojan horse Downloader.Generic13.CHXB.dropper
66.67%

Malwarebytes
PUP.Optional.DomaIQ, PUP.Optional.BundleInstaller.A, PUP.Optional.DomalQ, PUP.Optional.InstallRex, PUP.Optional.Dropper.BL
63.89%

Sophos
Generic PUA CH, DomainIQ pay-per install, Generic PUA PN, Generic PUA PH, SoftPulse, Troj/MSIL-MD, Generic PUA PF, PUA 'DomainIQ pay-per install'
63.89%

McAfee
RDN/Generic PUP.x!bv3, RDN/Generic PUP.x!b2b, Adware-DomaIQ!17E61A5A5928, Adware-DomaIQ!47F1B4F1E5F8, Adware-DomaIQ!E67B3FE4C21C, SoftPulse
63.89%

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ, not-a-virus:AdWare.Win32.Lollipop, not-a-virus:HEUR:AdWare.MSIL.DomaIQ
61.11%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/MSIL.DomaIQ, GrayWare[AdWare:not-a-virus]/Win32.Lollipop, Trojan[:HEUR]/Win32.AGeneric, Trojan/Win32.TGeneric
61.11%

K7 Gateway Antivirus
Unwanted-Program , Trojan
61.11%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious.H, RDN/Generic PUP.x!b2b, Heuristic.LooksLike.Win32.Suspicious.I, Socrydo, CryptDomaIQ
58.33%

K7 AntiVirus
Unwanted-Program , Trojan
58.33%

Panda Antivirus
PUP/MultiToolbar.A, Trj/Genetic.gen
55.56%

Agnitum Outpost
PUA.DomaIQ, PUA.Lollipop, Riskware.Agent, Packed/PECompact
52.78%

Dr.Web
Adware.Downware.2259, Adware.Downware.2479, Trojan.DownLoader9.62498, Trojan.DownLoader11.4884, Trojan.DownLoader9.45575
52.78%

The domain downloads.gufile.com has been seen to resolve to the following 8 IP addresses.

ec2-52-10-139-14.us-west-2.compute.amazonaws.com
May 21, 2015

ec2-52-10-43-205.us-west-2.compute.amazonaws.com
May 21, 2015

ec2-54-187-111-79.us-west-2.compute.amazonaws.com
August 12, 2014

ec2-54-218-87-136.us-west-2.compute.amazonaws.com
August 12, 2014

ec2-54-187-72-39.us-west-2.compute.amazonaws.com
June 5, 2014

ec2-54-201-20-36.us-west-2.compute.amazonaws.com
May 23, 2014

ec2-54-201-62-44.us-west-2.compute.amazonaws.com
March 6, 2014

ec2-54-218-48-102.us-west-2.compute.amazonaws.com
February 27, 2014

File downloads found at URLs served by downloads.gufile.com.

1 / 68      (Adware)
http://downloads.gufile.com/.../google-chrome-dev.exe  (c41bac9e11d7cf605d17f5e25b6b0be0)

1 / 68      (Adware)
http://downloads.gufile.com/.../imvu.exe  (e3678ae5263c3b8214aabe0bca540cfc)

1 / 68      (Adware)
http://downloads.gufile.com/.../itunes.exe  (f5da6f14ca2b9d6b4e29a055138019f4)

1 / 68      (Adware)

1 / 68      (Adware)
http://downloads.gufile.com/.../avast.exe  (9563ffc4ca6ad03a59415847b8368dfc)

13 / 68    (Adware)

42 / 68    (Adware)
http://downloads.gufile.com/.../microsoft-publisher.exe  (d765614b99ca02d71c4b2815763af240)

24 / 68    (PUP)
http://downloads.gufile.com/.../Microsoft-Silverlight.exe  (48893c6330371cd75c3c27dcc45b141f)

37 / 68    (Adware)
http://downloads.gufile.com/.../microsoft-office-2010.exe  (a5988449deb3c84ea0964d319890128d)

10 / 68    (Adware)
http://downloads.gufile.com/.../whatsapp.exe  (c67fa4dbc065c4ee8a2f2db9169b8218)

1 / 68      (Adware)
http://downloads.gufile.com/.../quicktime.exe  (a53391066920a15973087174ad94e89c)

33 / 68    (Adware)
http://downloads.gufile.com/.../microsoft-office-2013.exe  (4c9d4bf0ae401848ed0ba81c9abe1bdd)

18 / 68    (Adware)
http://downloads.gufile.com/.../itunes32_64.exe  (87ba642a37ae47fc31ce65de099d56e7)

36 / 68    (Adware)
http://downloads.gufile.com/.../free-yahtzee-game.exe  (552b604bccda10d8386aaa92b82b015b)

32 / 68    (Adware)
http://downloads.gufile.com/.../samsung-kies.exe  (c896cde9294706322c6bda694fce0ad2)

14 / 68    (Adware)
http://downloads.gufile.com/.../free-opener.exe  (7ec3c77a4f3ac97746a6b22f1ab7ae56)

24 / 68    (Adware)
http://downloads.gufile.com/.../mozilla-thunderbird.exe  (3d0e5b119ea4a60be2f8f6a645346009)

12 / 68    (Adware)
http://downloads.gufile.com/.../ask-com-toolbar.exe  (474a03696821339f0cfafa4fb3c4cbfb)

1 / 68      (Adware)
http://downloads.gufile.com/.../opengl.exe  (983a9fdc844273aadec3b72d4b306efa)

The following 9 files have been seen to comunicate with downloads.gufile.com in live environments.

Remove Malware from downloads.gufile.com - Powered by Reason Core Security