bsods.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain bsods.net is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Friday, October 2, 2015

Expires date:
Sunday, October 2, 2016

Updated date:
Wednesday, April 6, 2016

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc., US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Reimage (L), PUP.Reimage.ReimageR.Installer.Meta (L), PUP.Reimage.Installer.Meta (L)
100.00%

Dr.Web
riskware program Program.Unwanted.493, riskware program Program.Unwanted.1470
66.67%

Bkav FE
W32.HfsAdware
33.33%

McAfee
Artemis!72CB31555DA5
33.33%

Malwarebytes
PUP.Optional.ReImageRepair.A
33.33%

ESET NOD32
Detection.Undefined
33.33%

Fortinet FortiGate
Riskware/ReImageRepair
33.33%

Baidu Antivirus
PUA.Win32.ReImageRepair
33.33%

Trend Micro House Call
Suspicious_GEN.F47V0520
33.33%

Kaspersky
not-a-virus:AdWare.Win32.Pibee
33.33%

The domain bsods.net has been seen to resolve to the following 2 IP addresses.

June 8, 2016

June 8, 2016

File downloads found at URLs served by bsods.net.

2 / 68      (PUP)
http://bsods.net/.../download  (reimagerepair.exe)

1 / 68      (PUP)
http://bsods.net/.../download  (reimagerepair.exe)

10 / 68    (PUP)
http://bsods.net/.../download  (reimagerepair.exe)

URL:
http://bsods.net/

Title:
“Home - bsods.net bsods.net”

SSL certificate subject:
CN=sni176541.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx (PHP/5.6.19)

Facebook:
Likes:  11
Shares:  1

Statistics above are for the previous month of March 2024.