50.7.28.2

FDCservers.net

IP Address Information

The Internet Service Provider (ISP) that owns the network address of 50.7.28.2 is FDCservers.net and located in Illinois within the United States. Currently there are 10 domain names that utilize this address. The primary domain hosted by this IP is dn.yourfiledownloader.com along with 9 other domains which are known adware distribution web sites. The address and domain is leased to Via Advertising Group Limited.
Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ViaAdvertisingGroupLimited.Q, PUP.ViaAdvertisingGroupLimited.R, PUP.ViaAdvertisingGroupLimited., PUP.ViaAdvertisingGroupLimited.P, PUP.ViaAdvertisingGroupLimited.n, PUP.ViaAdvertisingGroupLimited.l, PUP.ViaAdvertisingGroupLimited.j, PUP.ViaAdvertisingGroupLimited.CC, PUP.ViaAdvertisingGroupLimited.Z, PUP.Installer.ViaAdvertisingGroupLimited.e
100.00%

VIPRE Antivirus
Via Advertising, Threat.4758264
87.50%

avast!
Win32:Downloader-UBW [Adw], Win32:PUP-gen [PUP], Win32:Downloader-UEO [PUP], Win32:Downloader-UGW [PUP]
83.33%

Dr.Web
Adware.Downware.1140, Adware.Babylon.4, Adware.Downware.1451, Tool.DownLoader.42, Tool.DownLoader.45, Threat.Undefined, Adware.Downware.9447
79.17%

ESET NOD32
Win32/YourFileDownloader (variant), Win32/ExpressDownloader (variant)
79.17%

Trend Micro House Call
TROJ_GEN.F47V0623, TROJ_SPNR.08JP12, TROJ_GEN.F47V0827, TROJ_SPNV.03KD13, TROJ_GEN.F47V0920, TROJ_GEN.F47V0607, TROJ_SPNR.08JG12, TROJ_SPNR.08HQ12
66.67%

McAfee
Artemis!BA792B193973, Artemis!F419F8A7C53E, Artemis!CB29C630728E, Artemis!ACD966385438, Artemis!91F5287BC48E, Artemis!E35EA3EA7503, Artemis!1BE7D1994F2A, Artemis!23D3A26BA0FE
62.50%

McAfee Web Gateway
Artemis!BA792B193973, Artemis!F419F8A7C53E, Artemis!CB29C630728E, Artemis!ACD966385438, Artemis!91F5287BC48E, Artemis!E35EA3EA7503
62.50%

K7 AntiVirus
Riskware, Unwanted-Program , Riskware , Trojan , Backdoor
58.33%

Sophos
YourFile Downloader, Generic PUA GH, Generic PUA KH, Mal/Generic-S, Generic PUA IM
54.17%

The following domains resolved to the IP address 50.7.28.2.

File URLs download from 50.7.28.2.

30 / 68    (Adware)

18 / 68    (Adware)

8 / 68      (Adware)

 
Latest 30 of 1,313 download URLs

The geographical location of this IP address.

Country:
United States (US)

Region:
Illinois

City:
Chicago

Coordinates:
41.8782, -87.6254

The ARIN network assigned organization for IP address 50.7.28.2.

Org name:
FDCservers.net

Org identifier:
FDCSE

Org country:
United States (US)

Org region:
Illinois

Org city:
Chicago

Org address:
141 W Jackson Blvd. #1135

ARIN WHOIS:
NetRange: 50.7.0.0 - 50.7.255.255
CIDR: 50.7.0.0/16
OriginAS: AS30058
NetName: FDCSERVERS
NetHandle: NET-50-7-0-0-1
Parent: NET-50-0-0-0-0
NetType: Direct Allocation
RegDate: 2010-10-18
Updated: 2012-02-24
Ref: http://whois.arin.net/rest/net/NET-50-7-0-0-1

OrgName: FDCservers.net
OrgId: FDCSE
Address: 141 W Jackson Blvd. #1135
City: Chicago
StateProv: IL
PostalCode: 60604
Country: US
RegDate: 2003-05-20
Updated: 2012-03-28
Ref: http://whois.arin.net/rest/org/FDCSE

ReferralServer: rwhois://rwhois.fdcservers.net:4321

OrgAbuseHandle: ABUSE438-ARIN
OrgAbuseName: ABUSE department
OrgAbusePhone: +1-312-423-6675
OrgAbuseEmail: abuse@fdcservers.net
OrgAbuseRef: http://whois.arin.net/rest/poc/ABUSE438-ARIN

OrgNOCHandle: TECHS72-ARIN
OrgNOCName: Tech Support
OrgNOCPhone: +1-312-423-6675
OrgNOCEmail: support@fdcservers.net
OrgNOCRef: http://whois.arin.net/rest/poc/TECHS72-ARIN

OrgTechHandle: TECHS72-ARIN
OrgTechName: Tech Support
OrgTechPhone: +1-312-423-6675
OrgTechEmail: support@fdcservers.net
OrgTechRef: http://whois.arin.net/rest/poc/TECHS72-ARIN


Autonomous System Assignment
ASNumber:
6461

ASName:
MFNX MFN - Metromedia Fiber Network

ASHandle:
AS6461

Remove Malware from 50.7.28.2 - Powered by Reason Core Security