get.zoomdownloader.com

FUSION INSTALL  (via a Proxy Registrant)

Domain Information

The domain get.zoomdownloader.com is registered by proxy through GODADDY.COM, LLC and was originally registered in January of 2012. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network. The domain is associated with the publisher FUSION INSTALL who is located in Kansas City, Missouri in the United States.
Remove Malware from get.zoomdownloader.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Friday, January 13, 2012

Expires date:
Friday, January 13, 2017

Updated date:
Monday, January 25, 2016

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.TINYINSTALLER.R, Threat.Win.Reputation.IMP, PUP.Installer.ExpressInstall.R, PUP.Installer.Adknowledge, PUP.Adknowledge.TINYINSTALLER.Installer (M)
96.43%

Comodo Security
TrojWare.Win32.Kryptik.BLXF, Application.Win32.Adware.iBryte.BAA, Application.Win32.Adware.iBryte.BC
96.43%

Dr.Web
Adware.Downware.1554, Adware.Downware.1602, Trojan.Packed.25262, Adware.Downware.1563, Adware.Downware.1554, Trojan.Packed.24939
96.43%

Vba32 AntiVirus
AdWare.iBryte, SScope.Malware-Cryptor.iBryte, Trojan.Buzus
96.43%

Rising Antivirus
PE:Trojan.Injector!1.9C6C, PE:Trojan.Kryptik!6.53F, PE:Trojan.Kryptik!6.52D, PE:Malware.Graftor!6.51B
96.43%

AVG
Skodna.Generic, Adware Skodna.Generic.APN, Adware Skodna.Generic.AQQ, Adware Skodna.Generic.AOZ, Adware Skodna.Generic.APZ
96.43%

Avira AntiVirus
APPL/iBryte.Gen, ADWARE/Adware.Gen7
96.43%

G Data
Win32.Adware.IBryte, Win32.Adware.Ibryte, Gen:Variant.Adware.Kazy.293324, Win32.Application.Ibryte.AF, Gen:Variant.Adware.Kazy.547631
96.43%

Malwarebytes
PUP.Optional.iBryte, PUP.Optional.OptimumInstaller.A, PUP.Optional.ExpressInstall.A
92.86%

avast!
Win32:IBryte-BY [PUP], IBryte-GJ [PUP], Win32:IBryte-BT [PUP], Win32:IBryte-GJ [PUP]
92.86%

Agnitum Outpost
Riskware.AdWare, Trojan.Buzus
92.86%

VIPRE Antivirus
Optimum Installer, Trojan.Win32.Generic, Threat.4778314, Trojan.Win32.Kryptik.blxe, Threat.4793587
92.86%

Sophos
iBryte Optimum Installer, PUA 'iBryte Optimum Installer'
92.86%

Jiangmin
Adware/iBryte.grvw, Adware/iBryte.grvh, Trojan/Buzus.ayxo, Trojan/Buzus.ayzi, Trojan/Buzus.ayye, Trojan/Buzus.ayyg
92.86%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud), Win32.Troj.iBryte.j.(kcloud)
92.86%

The domain get.zoomdownloader.com has been seen to resolve to the following 16 IP addresses.

ip-184-168-221-51.ip.secureserver.net
February 1, 2016

ec2-52-20-182-179.compute-1.amazonaws.com
December 16, 2015

ec2-52-20-167-28.compute-1.amazonaws.com
December 15, 2015

ec2-52-20-25-93.compute-1.amazonaws.com
October 29, 2015

ec2-54-85-105-202.compute-1.amazonaws.com
October 19, 2015

ec2-52-2-5-65.compute-1.amazonaws.com
September 16, 2015

ec2-54-173-230-197.compute-1.amazonaws.com
July 16, 2015

ec2-52-4-182-78.compute-1.amazonaws.com
June 26, 2015

ec2-52-7-229-200.compute-1.amazonaws.com
June 19, 2015

ec2-50-19-244-90.compute-1.amazonaws.com
January 8, 2015

ec2-107-21-120-240.compute-1.amazonaws.com
October 24, 2014

ec2-50-16-246-149.compute-1.amazonaws.com
September 9, 2014

ec2-54-197-252-60.compute-1.amazonaws.com
August 13, 2014

ec2-184-73-200-83.compute-1.amazonaws.com
July 3, 2014

ec2-50-17-229-236.compute-1.amazonaws.com
April 4, 2014

ec2-107-21-92-183.compute-1.amazonaws.com
December 26, 2013

File downloads found at URLs served by get.zoomdownloader.com.

The following 2 files have been seen to comunicate with get.zoomdownloader.com in live environments.

URL:
http://get.zoomdownloader.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)

Remove Malware from get.zoomdownloader.com - Powered by Reason Core Security