downloads205.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain downloads205.com is registered by proxy through ENOM, INC. and was originally registered in November of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Roubaix, Nord-Pas-De-Calais within France which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Nord-Pas-De-Calais, France (FR)

Create date:
Thursday, November 28, 2013

Expires date:
Monday, November 28, 2016

Updated date:
Thursday, October 29, 2015

Scanner detections:
Detections  (85% detected)

Scan engine
Details
Detections

ESET NOD32
MSIL/Adware.Colooader (variant), Win32/AdWare.Linkular.AH
76.47%

Reason Heuristics
PUP.QUALITYSCORESL.P, PUP.QUALITYSCORESL.N, PUP.QUALITYSCORESL.D, PUP.QUALITYSCORESL.T, PUP.QUALITYSCORESL.F, PUP.QUALITYSCORESL.I, PUP.QUALITYSCORE (M)
76.47%

Malwarebytes
PUP.Optional.QualityScore, PUP.Optional.PreDownload.A, PUP.Optional.QualScore
64.71%

Comodo Security
ApplicUnwnt
58.82%

Trend Micro House Call
TROJ_GEN.F47V0308, TROJ_GEN.F47V0328, TROJ_GEN.F47V0401, TROJ_GEN.F47V0404, TROJ_GEN.F47V0409, TROJ_GEN.R047H07CU14, TROJ_GEN.F47V0411
52.94%

Qihoo 360 Security
Unnamed.Threat, Win32/Trojan.Adware.d7a
52.94%

VIPRE Antivirus
MSIL.Adware.Colooader, Trojan.Win32.Generic, Threat.4763461
35.29%

XVirus List
Win.Detected, Win64.Detected
11.76%

Fortinet FortiGate
Adware/Colooader
11.76%

AVG
Downloader
11.76%

McAfee
Artemis!6850AA7FF042, Virus.W32/Swisyn.ag
11.76%

McAfee Web Gateway
Artemis!6850AA7FF042
5.88%

Microsoft Security Essentials
Threat.Undefined
5.88%

ESET NOD32
Win32/VB.OSK trojan
5.88%

F-Prot
W32/VB.AD.gen
5.88%

The domain downloads205.com has been seen to resolve to the following 3 IP addresses.

April 15, 2016

198-57-180-233.unifiedlayer.com
September 4, 2014

ns3262829.ip-37-59-9.eu
March 14, 2014

File downloads found at URLs served by downloads205.com.

2 / 68      (Adware)

10 / 68    (Malware)
http://downloads205.com/bin/.../movie-maker-1-6.exe  (50589d4803d977ab406dfe5ac6e811b2)

1 / 68      (Adware)

0 / 68
http://downloads205.com/bin/.../audacity.exe  (microsoft-office-2010.exe)

0 / 68
http://downloads205.com/bin/.../roblox.exe  (70729a596151e135383266506a389724)

2 / 68      (Adware)

2 / 68      (Adware)

2 / 68      (Adware)

2 / 68      (Adware)

11 / 68    (Adware)

6 / 68      (Adware)

2 / 68      (Adware)

6 / 68      (Adware)

11 / 68    (Adware)
http://downloads205.com/bin/.../songbird.exe  (bluestacks-app-player.exe)

7 / 68      (Adware)

6 / 68      (Adware)

2 / 68      (Adware)
http://downloads205.com/bin/.../auslogics-boostspeed.exe  (5aaacded322c8c3b5876ea899989323a)

9 / 68      (Adware)

6 / 68      (Adware)

6 / 68      (Adware)

2 / 68      (Adware)

9 / 68      (Adware)

9 / 68      (Adware)

9 / 68      (Adware)

9 / 68      (Adware)

3 / 68      (Adware)

2 / 68      (Adware)

3 / 68      (Adware)

9 / 68      (Adware)
http://downloads205.com/bin/.../opera.exe  (7c1404d5e55d7a5d7de0b79a43faeaf7)

 
Latest 30 of 52 download URLs

The following 26 files have been seen to comunicate with downloads205.com in live environments.

 
Latest 20 of 26 files

February 27, 2016

URL:
http://downloads205.com/

Google Analytics:
UA-48689684

Title:
“downloads205.com”

Web server:
nginx

30 of 618 related domains