files5.freega.me

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain files5.freega.me is registered by proxy through GoDaddy.com, LLC R41-ME (146) and was originally registered in September of 2011. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the SoftLayer Technologies Inc. network.
Remove Malware from files5.freega.me - Powered by Reason Core Security
Registrar:
GoDaddy.com, LLC R41-ME (146)

Server location:
Texas, United States (US)

Create date:
Friday, September 30, 2011

Expires date:
Friday, September 30, 2016

Updated date:
Thursday, October 01, 2015

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.

Root domain:

Scanner detections:
Detections  (95% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.DownloadAdmin.X, PUP.Installer.DownloadAdmin.S, PUP.Installer.DownloadAdmin.R, PUP.DownloadAdmin.Bundler.Installer.Meta (M), PUP.Installer.DownloadAdmin.M, PUP.Installer.DownloadAdmin.CC, PUP.Installer.DownloadAdmin.e, PUP.Installer.DownloadAdmin.V, PUP.Tightrope.Bundler, PUP.Installer.DownloadAdmin.U, PUP.Bundler.Tightrope, PUP.TomorrowSoftware.GOLDENBANNERS.Bundler (M), PUP.Tightrope.Zoobam.Bundler (M), PUP.Tightrope.DownloadAdmin.Bundler (M)
97.30%

herdProtect (fuzzy)
a variant of f8ec604fb7009fe15c78f71c4f6ec1f5b9d9d134, a variant of a9a182a69f5a593ca2b4208bde80862379dbb76b, a variant of fa6e02852e42170564ed963284be5e74cf076679
56.76%

VIPRE Antivirus
DownloadAdmin, Threat.4783369, Threat.4150696
51.35%

Sophos
Download Admin
48.65%

Dr.Web
Adware.Downware.2220, Adware.DAdmin.151, Threat.Undefined, Adware.Downware.411, Adware.GameVance.158, Adware.Downware.946
48.65%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
48.65%

NANO AntiVirus
Trojan.Win32.Downware.crgjbr, Riskware.Win32.Downware.crgjbr, Trojan.Win32.Downware.bqhlba
45.95%

ESET NOD32
Win32/DownloadAdmin
40.54%

Malwarebytes
PUP.Optional.DownloadAdmin
37.84%

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
24.32%

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application, Win32/Exent.A potentially unwanted application
18.92%

Trend Micro House Call
Suspicious_GEN.F47V0706, TROJ_GEN.F47V0512
16.22%

SUPERAntiSpyware
Trojan.Agent/Gen-Artemis
13.51%

Avira AntiVirus
ADWARE/Adware.Gen
10.81%

F-Secure
Adware:W32/WebInstallBundle
10.81%

The domain files5.freega.me has been seen to resolve to the following 4 IP addresses.

50.22.63.138-static.reverse.softlayer.com
December 1, 2014

50.22.63.140-static.reverse.softlayer.com
December 1, 2014

50.97.63.217-static.reverse.softlayer.com
April 11, 2014

108.168.160.45-static.reverse.softlayer.com
April 11, 2014

File downloads found at URLs served by files5.freega.me.

1 / 68      (Adware)
http://files5.freega.me/dl?bc=13908&geo  (puzzleexpress-setup.exe)

0 / 68
http://files5.freega.me/dl?bc=972879  (lettersfromnowhere2-setup.exe)

2 / 68      (inconclusive)
http://files5.freega.me/dl?bc=13734&geo  (mystery-of-shark-island.exe)

1 / 68      (Adware)
http://files5.freega.me/dl?bc=13614&geo  (mahjonggartifacts-setup.exe)

1 / 68      (Adware)

10 / 68    (Adware)
http://files5.freega.me/dl?bc=13500&geo  (littleshopmemories-setup.exe)

13 / 68    (Adware)
http://files5.freega.me/dl?bc=13098&geo  (flowerparadise-setup.exe)

1 / 68      (Adware)
http://files5.freega.me/dl?bc=13608&geo  (mahjongworld-setup.exe)

1 / 68      (Adware)

10 / 68    (Adware)
http://files5.freega.me/dl?bc=12798&geo  (dinerdashfloonthego-setup.exe)

1 / 68      (Adware)
http://files5.freega.me/dl?bc=13398&geo  (jewelquest2-setup.exe)

1 / 68      (Adware)
http://files5.freega.me/dl?bc=12708&geo  (cookingacademy-setup.exe)

1 / 68      (Adware)
http://files5.freega.me/dl?bc=10671&geo  (secretofmargravemanor-setup.exe)

1 / 68      (Adware)
http://files5.freega.me/dl?bc=10667&geo  (magicencyclopediamoonlight-setup.exe)

16 / 68    (Adware)

16 / 68    (Adware)
http://files5.freega.me/dl?bc=10659&geo  (mahjonggartifacts-setup.exe)

10 / 68    (Adware)
http://files5.freega.me/dl?bc=13614  (mahjonggartifacts-setup.exe)

11 / 68    (Adware)
http://files5.freega.me/dl?bc=580035&geo  (ritajamesandtheracetoshangrila-setup.exe)

11 / 68    (Adware)
http://files5.freega.me/dl?bc=580149&geo  (tricksandtreats-setup.exe)

1 / 68      (PUP)
http://files5.freega.me/dl?bc=12270&geo  (aerialmahjong-setup.exe)

1 / 68      (Adware)
http://files5.freega.me/dl?bc=13428&geo  (jigsawworld-setup.exe)

1 / 68      (Adware)
http://files5.freega.me/dl?bc=12516&geo  (birdsonawire-setup.exe)

The following 60 files have been seen to comunicate with files5.freega.me in live environments.

 
Latest 20 of 63 files

30 of 45 related domains

Remove Malware from files5.freega.me - Powered by Reason Core Security