www.downloadspring.com

James Guel

Domain Information

The domain www.downloadspring.com registered by James Guel was initially registered in July of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Remove Malware from www.downloadspring.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Monday, July 15, 2013

Expires date:
Saturday, July 15, 2017

Updated date:
Sunday, December 08, 2013

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (72% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.OOOKango.P, PUP.Optional.Installer, PUP.DownloadShield.Installer (M)
85.71%

VIPRE Antivirus
InstallCore, Conduit, DownloadShield
11.43%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
11.43%

McAfee Web Gateway
Artemis, BehavesLike.Win32.AdwareSweet.dc, BehavesLike.Win32.AdwareMonetizer.dc
8.57%

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
8.57%

Dr.Web
Win32.Sector.21, Trojan.InstallCore.11
5.71%

ESET NOD32
Win32/OpenCandy (variant), Win32/DownWare.S potentially unwanted
5.71%

Bkav FE
W32.HfsAdware
5.71%

NANO AntiVirus
Riskware.Nsis.Dloader.dvvnkj
5.71%

AVG
MultiBundle
5.71%

Avira AntiVirus
W32/Sality.AT
2.86%

F-Prot
W32/Sality.gen2
2.86%

F-Secure
Win32.Sality.3
2.86%

Microsoft Security Essentials
Threat.Undefined
2.86%

Antiy Labs AVL
Trojan/Win32.SGeneric
2.86%

The domain www.downloadspring.com has been seen to resolve to the following 3 IP addresses.

July 1, 2015

July 1, 2015

p3nlhg146c1146.shr.prod.phx3.secureserver.net
February 6, 2014

File downloads found at URLs served by www.downloadspring.com.

1 / 68      (Adware)

1 / 68      (Adware)
http://www.downloadspring.com/.../Modio_Setup.exe  (db7ae72caea3e27310ae7f70607a0cc6)

1 / 68      (Adware)
http://www.downloadspring.com/.../FreeCell_Setup.exe  (4609478966b6a9b6471762fbcb53fc3c)

1 / 68      (Adware)
http://www.downloadspring.com/.../FreeCell_Setup.exe  (e63d1c48ae4c4ddc8a632ff9c5fda4a4)

0 / 68
http://www.downloadspring.com/.../DayZSetup.msi  (dotjosh.dayzcommander.installer.msi)

0 / 68
http://www.downloadspring.com/.../downloadarch.php  (dotjosh.dayzcommander.installer.msi)

5 / 68      (false positives)

1 / 68      (Adware)
http://www.downloadspring.com/.../Elsword_Setup.exe  (7b19a8fd4595c413077855590979137d)

1 / 68      (Adware)
http://www.downloadspring.com/.../Ventrilo_Setup.exe  (e791d706d3c17abc7386495192f1c1ee)

0 / 68
http://www.downloadspring.com/.../VentriloSetup.exe  (ventrilo-3.0.8-windows-i386.exe)

1 / 68      (Adware)
http://www.downloadspring.com/.../Mineshafter_Setup.exe  (d9f11b963425db469b1f59b96db250e6)

1 / 68      (Adware)
http://www.downloadspring.com/.../Lightworks_Setup.exe  (620d9e2622d5173bae54fffcb8942675)

1 / 68      (Adware)
http://www.downloadspring.com/.../Terraria_Setup.exe  (6ce62d0d44967d19a85bc25517c58637)

1 / 68      (PUP)

1 / 68      (Adware)
http://www.downloadspring.com/.../Terraria_Setup.exe  (b26d69d1eee89ec5ea8cb753d3820354)

1 / 68      (Adware)

9 / 68      (PUP)

1 / 68      (Adware)
http://www.downloadspring.com/.../DayZ_Setup.exe  (eef661d52e10ee4abadd5a19e22f7b7b)

1 / 68      (Adware)
http://www.downloadspring.com/.../Mineshafter_Setup.exe  (c82d69a6531b200c7ed334ea09a97dc2)

1 / 68      (PUP)

1 / 68      (Adware)
http://www.downloadspring.com/.../Modio_Setup.exe  (6d18a8430e98f1de9dc5fb4e72959ac5)

0 / 68
http://www.downloadspring.com/.../FreeCellSetup.exe  (free_freecell_solitaire2015_v300_setup.exe)

1 / 68
http://www.downloadspring.com/.../KikSetup.exe  (cce9b58d584679fdaf3a8a9d41569509)

0 / 68
http://www.downloadspring.com/BlueStacks.exe  (bluestacks-splitinstaller_native.exe)

0 / 68

0 / 68

1 / 68      (Adware)
http://www.downloadspring.com/.../WeChat_Setup.exe  (5b5c475ec50c9dc8c8a6993a089c5e0d)

1 / 68      (Adware)

 
Latest 30 of 52 download URLs

URL:
http://www.downloadspring.com/

Title:
“DownloadSpring”

SSL certificate subject:
CN=sni100815.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx

Compete.com:
US visitors:  140,886

Statistics are for the previous month.

Remove Malware from www.downloadspring.com - Powered by Reason Core Security