www.downloadspring.com

James Guel

Domain Information

The domain www.downloadspring.com registered by James Guel was initially registered in July of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Monday, July 15, 2013

Expires date:
Saturday, July 15, 2017

Updated date:
Sunday, December 08, 2013

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (79% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.DownloadShield.Bundle.Installer.Meta (M), PUP.DownloadShield.Installer (M), PUP.Download.Installer (M), PUP (M)
90.48%

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
9.52%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
7.14%

ViRobot
Backdoor.Win32.A.BlackHole.2197393[UPX], Trojan.Win32.A.Downloader.64873[h]
4.76%

Antiy Labs AVL
Virus/Win32.Gobi.gen, Trojan/Win32.SGeneric
4.76%

McAfee
Artemis!46E423B4733E, Artemis!EE08E021AD73
4.76%

VIPRE Antivirus
DownloadShield
4.76%

McAfee Web Gateway
BehavesLike.Win32.AdwareSweet.dc
4.76%

AVG
MultiBundle, Generic
4.76%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A
2.38%

F-Secure
Application:W32/Generic.70053c248f!Online
2.38%

Fortinet FortiGate
Riskware/WiFiRadar
2.38%

Bkav FE
W32.Clodffd.Trojan
2.38%

Malwarebytes
PUP.Adware.Agent
2.38%

Trend Micro House Call
Suspicious_GEN.F47V0430
2.38%

The domain www.downloadspring.com has been seen to resolve to the following 3 IP addresses.

July 1, 2015

July 1, 2015

p3nlhg146c1146.shr.prod.phx3.secureserver.net
February 6, 2014

File downloads found at URLs served by www.downloadspring.com.

1 / 68      (Adware)
http://www.downloadspring.com/.../EasyWiFiRadar_Setup.exe  (9e0feea41386b0260bab24b0456a4e46)

1 / 68      (Adware)
http://www.downloadspring.com/.../Pixlr-Setup.exe  (d5f062e2316fcc540c3552d6e5e2c014)

1 / 68      (Adware)
http://www.downloadspring.com/.../Kik-Setup.exe  (11fb4393f2ec65342ae37ca1c89480ab)

0 / 68
http://www.downloadspring.com/ca/.../downloadarch.php  (dotjosh.dayzcommander.installer.msi)

2 / 68      (PUP)

2 / 68      (false positives)

3 / 68      (PUP)

1 / 68      (Adware)
http://www.downloadspring.com/.../FreeCell_Setup.exe  (4ac7edc1b25711f25ae8fbcfd03dbe37)

1 / 68      (Adware)
http://www.downloadspring.com/.../Kik-Setup.exe  (fbfb832ba10025d769b1482eee668e50)

1 / 68      (Adware)
http://www.downloadspring.com/.../Elsword-Setup.exe  (bf1fd78fc9f6512d853f7e8ee749e4d6)

1 / 68      (Adware)
http://www.downloadspring.com/.../Mineshafter-Setup.exe  (f482ce7f704c7fdcbf2384c34fac47a6)

1 / 68      (Adware)
http://www.downloadspring.com/.../Terraria-Setup.exe  (1feca39ca7a11b6da27dd6c0dfcb11e8)

1 / 68      (Adware)
http://www.downloadspring.com/.../Kik_Setup.exe  (6cd723156e941ce7c0a2914bfb3546e6)

0 / 68
http://www.downloadspring.com/.../MineshafterSetup.jar  (24e003229cb67b0d75e7aa5e6c2ae9b0)

0 / 68
http://www.downloadspring.com/.../downloadarch.php  (free_freecell_solitaire2015_v300_setup.exe)

1 / 68      (Adware)
http://www.downloadspring.com/.../Prezi-Setup.exe  (75dc70075e2d9947d48929df383ccbba)

1 / 68      (Adware)
http://www.downloadspring.com/.../Ventrilo-Setup.exe  (2117f3621dadffd2c83303a1900c2218)

1 / 68      (Adware)
http://www.downloadspring.com/.../DayZ-Setup.exe  (a93421c4f3586c35fb59f5aba2a6a9c1)

1 / 68      (Adware)
http://www.downloadspring.com/.../Mineshafter_Setup.exe  (7f7a9d3073d10da419f280edeb521299)

1 / 68      (Adware)
http://www.downloadspring.com/.../SeratoDJ-Setup.exe  (53cf7083840ab97c5441bd90954265e6)

10 / 68    (Adware)
http://www.downloadspring.com/.../FreeCell_Setup.exe  (ee08e021ad73b596c67e129998e0110c)

1 / 68      (Adware)
http://www.downloadspring.com/.../Modio-Setup.exe  (7b0a8ea1c8e319927d7393761c4811b8)

1 / 68      (Adware)
http://www.downloadspring.com/.../SeratoDJ_Setup.exe  (cf88d2442dc8b18636740db57c995de9)

1 / 68      (Adware)
http://www.downloadspring.com/.../SurgeonSimulator-Setup.exe  (a1b216cb-378a-22eb-b08a-6b394b7cc60e_1d1bf5d2685d4f7)

1 / 68      (Adware)
http://www.downloadspring.com/.../Terraria-Setup.exe  (d2a01288e51db69c9c99e924df702546)

1 / 68      (Adware)
http://www.downloadspring.com/.../Stellarium-Setup.exe  (2cffd284c5c388ccd7095401d3fd0ec8)

1 / 68      (Adware)
http://www.downloadspring.com/.../Lightworks-Setup.exe  (af252089b336cf1feb0b16b1583fdc6a)

1 / 68      (Adware)
http://www.downloadspring.com/.../SubwaySurfers_Setup.exe  (23b54a63585f6f22cb6120ba35e7695c)

1 / 68      (Adware)

 
Latest 30 of 174 download URLs

The following 4 files have been seen to comunicate with www.downloadspring.com in live environments.

URL:
http://www.downloadspring.com/

Title:
“DownloadSpring”

SSL certificate subject:
CN=sni100815.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx

Compete.com:
US visitors:  140,886

Statistics are for the previous month.