express-files.com

Faglaro Enterprises Limited

Domain Information

The domain express-files.com registered by Faglaro Enterprises Limited was initially registered in December of 2011 through INTERNET.BS CORP.. This domain has been known to host and distribute adware as well as other potentially unwanted software.
Remove Malware from express-files.com - Powered by Reason Core Security
Registrar:
INTERNET DOMAIN SERVICE BS CORP

Create date:
Tuesday, December 06, 2011

Expires date:
Tuesday, December 06, 2016

Updated date:
Saturday, December 12, 2015

ASN:
AS9498 BBIL-AP BHARTI Airtel Ltd.,IN

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

VIPRE Antivirus
ExpressFiles Installer, Threat.4783941
100.00%

Reason Heuristics
PUP.FaglaroEnterprisesLimited.Q, PUP.FaglaroEnterprisesLimited.L, PUP.FaglaroEnterprisesLimited.P, PUP.FaglaroEnterprisesLimited.S, PUP.FaglaroEnterprisesLimited.J, PUP.FaglaroEnterprisesLimited.M, PUP.FaglaroEnterprisesLimited.R, Adware.httpwwwexpressfiles, Win32.Generic.Installer.Meta, PUP.Blisbury.FaglaroEnterprises.Bundler (M)
100.00%

avast!
Win32:Downloader-TSH [PUP], Win32:Rootkit-gen [Rtk], Win32:Expressfiles-A [PUP]
100.00%

Sophos
Express Files
95.56%

Trend Micro House Call
TROJ_GEN.F47V0809, TROJ_GEN.F47V1123, TROJ_GEN.F47V1127, TROJ_GEN.F47V0721, TROJ_SPNV.03KB13, TROJ_GEN.F47V0922, TROJ_GEN.F47V1101, TROJ_GEN.F47V0821, TROJ_GEN.F47V1229
93.33%

Malwarebytes
PUP.Optional.ExpressFiles.A
93.33%

AVG
MalSign.Faglaro Enterprises Limited, Skodna.Generic_c
93.33%

G Data
Win32.Application.ExpressFiles, Win32.Application.ExpressDownloader
93.33%

Rising Antivirus
PE:PUF.ExpressFiles!1.9E64
93.33%

McAfee
Artemis!400F93A19DC0, Artemis!1FBDCF9C1254, Artemis!F6D0AA29E5A1, Artemis!0AC7EE6F0F3B, Artemis!AFDE4A33097C, Artemis!21E11F84FA19, PUP-FJJ!7CCC1B68B162
91.11%

McAfee Web Gateway
Artemis!400F93A19DC0, Artemis!1FBDCF9C1254, Artemis!F6D0AA29E5A1, Artemis!0AC7EE6F0F3B, Artemis!AFDE4A33097C, Artemis!21E11F84FA19
88.89%

Avira AntiVirus
Adware/ExpressFiles.DA, ADWARE/Adware.Gen2, ADWARE/BrowseFox.aox
88.89%

Dr.Web
Adware.Downware.1440, Adware.Downware.747, Adware.Downware.1872
88.89%

K7 AntiVirus
Unwanted-Program
86.67%

Fortinet FortiGate
Riskware/Agent, Riskware/ExpressFiles
86.67%

The domain express-files.com has been seen to resolve to the following 4 IP addresses.

ReasonOne
October 29, 2015

mail.express-files.com
August 26, 2014

June 20, 2014

199.195.194.4.static.midphase.com
December 26, 2013

File downloads found at URLs served by express-files.com.

38 / 68    (Adware)
http://express-files.com/EFinstaller.exe  (25d300ba7286cb76d58c2ab25800ec9e)

1 / 68      (PUP)
http://express-files.com/.../g_installer.exe  (aca950b1066825004e1deee1d290370d)

The following 2 files have been seen to comunicate with express-files.com in live environments.

September 5, 2014

February 6, 2014

December 26, 2013

December 28, 2013

Facebook:
Likes:  6,626
Shares:  3,445
Comments:  2,246

Statistics above are for the previous month of November 2016.

Remove Malware from express-files.com - Powered by Reason Core Security