downloadsave.info

1&1 Internet Inc

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Los Angeles, California within the United States which resides on the Hawk Host Inc. network.
Registrar:
1&1 Internet SE

Server location:
California, United States (US)

ASN:
AS20068 HAWKHOST - Hawk Host Inc., CA

Scanner detections:
Detections  (79% detected)

Scan engine
Details
Detections

ESET NOD32
multiple threats, Generik.FTCUYLC potentially unwanted application
87.50%

Microsoft Security Essentials
Threat.Undefined, BrowserModifier:Win32/Diplugem
75.00%

AVG
AdInject, Could be an adware AdInject, Could be an adware JS/AdInject, Adware AdPlugin.CSD
68.75%

Dr.Web
Adware.Plugin.31, Threat.Undefined, - infected archive c:\users\test\appdata\local\temp\5080a5a42c2f08f761486b18d1169901da269fc2 Win32.
62.50%

F-Prot
JS/MegaSearch.A.gen, W32/AdAgent.AL.gen
56.25%

Emsisoft Anti-Malware
Gen:Adware.MPlug
56.25%

avast!
Win32:MultiPlug-U [PUP]
56.25%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696
50.00%

Norman
Gen:Adware.MPlug.1
37.50%

Sophos
FastSave, MultiPlug, PUA 'MultiPlug' (of type Adware)
25.00%

MicroWorld eScan
Gen:Adware.MPlug.1
18.75%

K7 Gateway Antivirus
Unwanted-Program
18.75%

K7 AntiVirus
Unwanted-Program
18.75%

Bitdefender
Gen:Adware.MPlug.1
18.75%

NANO AntiVirus
Riskware.Script.Plugin.cqxkvi, Trojan.Script.Crossrider.cwbicn
18.75%

The domain downloadsave.info has been seen to resolve to the following 4 IP addresses.

198.252.107.5-static.reverse.arandomserver.com
June 24, 2016

198.252.101.177-static.reverse.arandomserver.com
February 8, 2016

November 10, 2014

March 14, 2014

File downloads found at URLs served by downloadsave.info.

The following file have been seen to comunicate with downloadsave.info in live environments.

URL:
http://downloadsave.info/

Title:
“All About Application Software |”

Web server:
LiteSpeed (PHP/5.4.45)