files5.safelink9.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain files5.safelink9.com is registered by proxy through GODADDY.COM, LLC and was originally registered in December of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the SoftLayer Technologies Inc. network.
Remove Malware from files5.safelink9.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Texas, United States (US)

Create date:
Thursday, December 26, 2013

Expires date:
Monday, December 26, 2016

Updated date:
Sunday, December 27, 2015

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.FullSpectrumInteractive.Y, PUP.Installer.Groovecom.Y, PUP.Tightrope.Bundler, PUP.Statscom.CC, PUP.FullSpectrumInteractive.Installer (M), PUP.DownloadAdmin.Groovecom.Installer (M), PUP.DownloadAdmin.FullSpectrumInteractive.Installer (M)
100.00%

VIPRE Antivirus
DownloadAdmin, Threat.4783369, Trojan.Win32.Generic, Threat.4150696
89.80%

Dr.Web
Win32.Sector.21, Adware.Downware.2220, Threat.Undefined, Adware.DAdmin.151, Trojan.Vittalia.2, Trojan.Vittalia.47
77.55%

NANO AntiVirus
Trojan.Win32.Downware.crgjbr, Riskware.Win32.Downware.crgjbr, Riskware.Win32.Downware.djahkt, Trojan.Win32.DAdmin.djhtdm
75.51%

Sophos
Download Admin, Generic PUA OK, PUA 'Download Admin'
73.47%

ESET NOD32
Win32/DownloadAdmin, Win32/DownloadAdmin (variant)
55.10%

F-Secure
Application.Bundler.I, Adware:W32/WebInstallBundle
48.98%

AVG
InstallC, Generic, MalSign.InstallC
44.90%

avast!
Adware-OH [Adw], NSIS:Adware-OH [Adw], Win32:Rootkit-gen [Rtk], Win32:GenMalicious-AGF [Trj], Win32:GenMalicious-AGK [Trj]
38.78%

McAfee Web Gateway
Artemis!60BC40941F0A, Artemis!39114A1017B8, Artemis!67DA572C248F, BehavesLike.Win32.Downloader.bc, BehavesLike.Win32.Downloader.jc
34.69%

Trend Micro House Call
TROJ_GEN.F47V0211, TROJ_GEN.F47V0412, TROJ_GEN.F47V0507, TROJ_GEN.F47V0424, Suspici.B577CD42, TROJ_GEN.F47V0116
32.65%

Avira AntiVirus
W32/Sality.AT, APPL/Downloader.Gen, ADWARE/Adware.Gen, PUA/DownloadAdmin.Gen
28.57%

Malwarebytes
PUP.Optional.BundleInstaller.A, PUP.Optional.InstallCore.A, PUP.Optional.DownloadAdmin
28.57%

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application, Win32/DownloadAdmin.H potentially unwanted application
26.53%

K7 AntiVirus
Unwanted-Program , Trojan
24.49%

The domain files5.safelink9.com has been seen to resolve to the following 4 IP addresses.

50.22.63.140-static.reverse.softlayer.com
August 28, 2014

50.22.63.138-static.reverse.softlayer.com
August 28, 2014

108.168.160.45-static.reverse.softlayer.com
March 14, 2014

50.97.63.217-static.reverse.softlayer.com
March 14, 2014

File downloads found at URLs served by files5.safelink9.com.

1 / 68      (Adware)
http://files5.safelink9.com/dl?bc=919437&aid=176681  (uplayermediaplayer-setup.exe)

1 / 68      (PUP)
http://files5.safelink9.com/dl?bc=919437&aid=513491  (uplayermediaplayer-setup.exe)

8 / 68      (PUP)
http://files5.safelink9.com/dl?bc=919437&aid=366151  (uplayermediaplayer-setup.exe)

15 / 68    (PUP)
http://files5.safelink9.com/dl?bc=969819&aid=674  (uplayermediaplayer-setup.exe)

10 / 68    (Adware)
http://files5.safelink9.com/dl?bc=919437&aid=30679  (uplayermediaplayer-setup.exe)

1 / 68      (PUP)

1 / 68      (Adware)

14 / 68    (Adware)
http://files5.safelink9.com/dl?bc=919437&aid=643711  (uplayermediaplayer-setup.exe)

12 / 68    (PUP)
http://files5.safelink9.com/dl?bc=919437&aid=582531  (uplayermediaplayer-setup.exe)

19 / 68    (Adware)

3 / 68      (Adware)
http://files5.safelink9.com/dl?bc=965998&aid=matomy  (uplayermediaplayer-setup.exe)

7 / 68      (PUP)
http://files5.safelink9.com/dl?bc=899882&aid=674  (uplayermediaplayer-setup.exe)

The following 60 files have been seen to comunicate with files5.safelink9.com in live environments.

 
Latest 20 of 63 files

30 of 45 related domains

Remove Malware from files5.safelink9.com - Powered by Reason Core Security