eac22216.down34bucket.us

mike peters

Domain Information

The domain eac22216.down34bucket.us registered by mike peters was initially registered in September of 2014 through INTERNET.BS CORP.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the SoftLayer Technologies Inc. network.
Registrar:
INTERNET.BS CORP.

Server location:
Texas, United States (US)

Create date:
Sunday, September 28, 2014

Expires date:
Sunday, September 27, 2015

Updated date:
Sunday, September 28, 2014

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.R2D2TechSoftware.T
100.00%

Malwarebytes
PUP.Optional.InstallBrain.A
100.00%

Dr.Web
Trojan.InstallBrain.1
100.00%

VIPRE Antivirus
InstallBrain
100.00%

AhnLab V3 Security
PUP/Win32.InstallBrain
100.00%

ESET NOD32
Win32/InstallBrain.CR potentially unwanted application
100.00%

AVG
Adware InstallBrain.BH
100.00%

Sophos
InstallBrain
100.00%

Comodo Security
Application.Win32.InstallBrain.BF
100.00%

MicroWorld eScan
Gen:Variant.Jaik.1231
100.00%

Bitdefender
Gen:Variant.Jaik.1231
100.00%

Lavasoft Ad-Aware
Gen:Variant.Jaik.1231
100.00%

Emsisoft Anti-Malware
Gen:Variant.Jaik.1231
100.00%

G Data
Gen:Variant.Jaik.1231
100.00%

Agnitum Outpost
PUA.InstallBrain
100.00%

The domain eac22216.down34bucket.us has been seen to resolve to the following 4 IP addresses.

50.97.49.242-static.reverse.softlayer.com
November 29, 2014

50.97.44.131-static.reverse.softlayer.com
November 29, 2014

174.37.181.31-static.reverse.softlayer.com
November 29, 2014

173.192.190.227-static.reverse.softlayer.com
November 29, 2014

File downloads found at URLs served by eac22216.down34bucket.us.

The following 17 files have been seen to comunicate with eac22216.down34bucket.us in live environments.

URL:
http://eac22216.down34bucket.us/

Title:
“Contact Us”

Web server:
nginx/1.2.4 (PHP/5.3.16)