extensionfile.net

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain extensionfile.net is registered by proxy through ENOM, INC. and was originally registered in March of 2008. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
Arizona, United States (US)

Create date:
Thursday, March 27, 2008

Expires date:
Monday, March 27, 2017

Updated date:
Friday, February 26, 2016

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.SmartPCSolutions.M, PUP.ParetoLogic.Optional.Installer.Meta (L)
100.00%

McAfee
Artemis!86274B082D4A
50.00%

K7 AntiVirus
Unwanted-Program
50.00%

K7 Gateway Antivirus
Unwanted-Program
50.00%

Comodo Security
UnclassifiedMalware
50.00%

McAfee Web Gateway
Artemis!86274B082D4A
50.00%

Sophos
PC Ultra Speed
50.00%

ESET NOD32
Win32/SpeedingUpMyPC (variant)
50.00%

Dr.Web
riskware program Program.Unwanted.686
50.00%

F-Secure
Gen:Adware.BrowseFox.1
50.00%

The domain extensionfile.net has been seen to resolve to the following 10 IP addresses.

June 27, 2016

June 27, 2016

January 4, 2016

January 4, 2016

October 13, 2015

October 13, 2015

February 7, 2014

February 7, 2014

December 26, 2013

December 26, 2013

File downloads found at URLs served by extensionfile.net.

3 / 68      (PUP)
http://extensionfile.net/recommends-regcure  (regcureprosetup_edcdfb75-9201-4924-b750-0fd0009942d1_.exe)

8 / 68      (PUP)

August 27, 2016

August 25, 2016

August 31, 2016

September 14, 2016

August 26, 2016

August 23, 2016

August 29, 2016

Latest 30 of 188 subdomains

URL:
http://extensionfile.net/

Google Analytics:
UA-71895931

Title:
“File extension database”

SSL certificate subject:
CN=ssl370177.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx (PHP/5.6.18)

Facebook:
Shares:  5

Statistics above are for the previous month of July 2017.