swiftdown.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain swiftdown.com is registered by proxy through GODADDY.COM, LLC and was originally registered in July of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dusseldorf, Nordrhein-Westfalen within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Nordrhein-Westfalen, Germany (DE)

Create date:
Monday, July 1, 2013

Expires date:
Friday, July 1, 2016

Updated date:
Thursday, July 2, 2015

ASN:
AS25074 INETBONE-AS MESH GmbH

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.SITEONSPOT.CC, Threat.Somoto.Bundler, PUP.Somoto.SITEONSPOT.Bundler (M), PUP.Somoto.Bundler (M)
100.00%

VIPRE Antivirus
Threat.4150696, BetterInstaller, Trojan.Win32.Generic
50.00%

MicroWorld eScan
Application.Bundler.Somoto.J
50.00%

Malwarebytes
PUP.Optional.Somoto.A
50.00%

SUPERAntiSpyware
PUP.Somoto/Variant
50.00%

Clam AntiVirus
Win.Adware.Somoto
50.00%

Kaspersky
not-a-virus:AdWare.Win32.Agent
50.00%

Bitdefender
Application.Bundler.Somoto.J
50.00%

NANO AntiVirus
Riskware.Nsis.Adware.dbnhrj
50.00%

Lavasoft Ad-Aware
Application.Bundler.Somoto.J
50.00%

Sophos
Somoto BetterInstaller
50.00%

F-Secure
Application.Bundler.Somoto.J
50.00%

Avira AntiVirus
APPL/Somoto.hzis, APPL/Somoto.Gen2
50.00%

Emsisoft Anti-Malware
Application.Bundler.Somoto
50.00%

AVG
Generic
50.00%

The domain swiftdown.com has been seen to resolve to the following IP address.

August 10, 2014

File downloads found at URLs served by swiftdown.com.

1 / 68      (Adware)
http://swiftdown.com/.../OnlineWeatherSetup-N3o6nRkm5.exe  (onlineweathersetup-n4qhhtvpr.exe)

1 / 68      (Adware)
http://swiftdown.com/.../OnlineWeatherSetup-N8Z4Y3ILI.exe  (de480a60c1c805788da7d7f636246f42)

1 / 68      (Adware)
http://swiftdown.com/.../OnlineWeatherSetup-NbqH0q2ZF.exe  (a2d536d2ffcd6997d34ec29500c80498)

24 / 68    (Adware)
http://swiftdown.com/.../OnlineWeatherSetup-NcQ45DBPL.exe  (d22e247d66b0727e825cf8d4fcb44c5c)

22 / 68    (Adware)
http://swiftdown.com/.../FLVPlayerSetup-NaQKFAPTW.exe  (a54c3c81a501a7dfe942fae75c0d7ba2)

20 / 68    (Adware)
http://swiftdown.com/.../OnlineWeatherSetup-N9KclVeiJ.exe  (1e89d4bccdb6f85b64f57b10631dbda4)

URL:
http://swiftdown.com/

Web server:
nginx