www.securefiledownload.com

HugeDomains.com

Domain Information

The domain www.securefiledownload.com registered by HugeDomains.com was initially registered in October of 2012 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Redwood City, California within the United States which resides on the SKYE network.
Registrar:
GODADDY.COM, LLC

Server location:
California, United States (US)

Create date:
Monday, October 15, 2012

Expires date:
Saturday, October 15, 2016

Updated date:
Wednesday, October 14, 2015

ASN:
AS26008 NOMINUM-SKYE1 - SKYE

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

F-Prot
W32/Backdoor2.HMGG, W32/InstallCore.W.gen, W32/InstallCore.W2.gen
83.33%

VIPRE Antivirus
Click run software, InstallCore
83.33%

Avira AntiVirus
APPL/Downloader.Gen6, ADWARE/InstallCore.Gen
83.33%

Sophos
Install Core Click run software
83.33%

McAfee
Artemis!39C4E0446E04, Artemis!61FFB4491916, Artemis!6D3163F81F82, Artemis!C9CBAF5F2BC5, Artemis!333C98ACE48D
83.33%

McAfee Web Gateway
Artemis!39C4E0446E04, Artemis!61FFB4491916, Artemis!6D3163F81F82, Artemis!C9CBAF5F2BC5, Artemis!333C98ACE48D
83.33%

Reason Heuristics
PUP.Clickrunsoftware.Y, PUP.Clickrunsoftware.J, PUP.installCore.Clickrunsoftware (M), PUP.InstallCore.ENG (M)
66.67%

Bkav FE
HW32.Laneul, HW32.CDB, W32.Clod504.Trojan, W32.Clod722.Trojan
66.67%

K7 AntiVirus
Unwanted-Program
66.67%

K7 Gateway Antivirus
Unwanted-Program
66.67%

Dr.Web
Adware.InstallCore.43, Adware.InstallCore.80, Trojan.Packed.2822
66.67%

Kingsoft AntiVirus
Win32.Troj.InstallCore.(kcloud), Win32.Troj.Generic.v.(kcloud), Win32.Troj.Generic.a.(kcloud)
66.67%

ESET NOD32
Win32/InstallCore (variant), Win32/InstallCore.AZ (variant)
66.67%

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
66.67%

Comodo Security
Application.Win32.WebToolbar.InstallCore.~A, Application.Win32.ClickRun.I, UnclassifiedMalware
50.00%

The domain www.securefiledownload.com has been seen to resolve to the following 8 IP addresses.

ec2-54-172-219-65.compute-1.amazonaws.com
May 25, 2016

ec2-52-20-195-18.compute-1.amazonaws.com
May 25, 2016

ec2-107-23-195-178.compute-1.amazonaws.com
May 25, 2016

ec2-54-152-144-243.compute-1.amazonaws.com
April 12, 2016

ec2-52-200-243-123.compute-1.amazonaws.com
April 12, 2016

ec2-52-73-136-140.compute-1.amazonaws.com
February 28, 2016

ec2-107-23-42-50.compute-1.amazonaws.com
February 28, 2016

search.dnsassist.verizon.net
February 7, 2014

File downloads found at URLs served by www.securefiledownload.com.

16 / 68    (PUP)

19 / 68    (PUP)

27 / 68    (Adware)

1 / 68      (Adware)

14 / 68    (PUP)
http://www.securefiledownload.com/.../FLVPlayer_v3.exe  (6d3163f81f823b59c41f6887dae11779)

24 / 68    (Adware)

The following 74 files have been seen to comunicate with www.securefiledownload.com in live environments.

 
Latest 20 of 74 files