tomdownload.net

Paul Haygarth

Domain Information

The domain tomdownload.net registered by Paul Haygarth was initially registered in August of 2004 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Thursday, August 5, 2004

Expires date:
Friday, August 5, 2016

Updated date:
Friday, September 25, 2015

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Reimage (L), Win32.Generic.Reimage.Installer.Meta, PUP.Reimage.ReimageR.Installer.Meta (L), PUP.Reimage.Installer.Meta (L)
100.00%

Dr.Web
riskware program Program.Unwanted.493, riskware program Program.Unwanted.1470
44.44%

Bkav FE
W32.HfsAdware
22.22%

McAfee
Artemis!72CB31555DA5, Artemis!D7830F8B35ED
22.22%

Malwarebytes
PUP.Optional.ReImageRepair.A
22.22%

Fortinet FortiGate
Riskware/ReImageRepair
22.22%

Baidu Antivirus
PUA.Win32.ReImageRepair
22.22%

Trend Micro House Call
Suspicious_GEN.F47V0520
22.22%

ESET NOD32
Detection.Undefined
11.11%

Kaspersky
not-a-virus:AdWare.Win32.Pibee
11.11%

ESET NOD32
Win32/ReImageRepair.F potentially unwanted
11.11%

Clam AntiVirus
Win.Trojan.Slugin-260
11.11%

The domain tomdownload.net has been seen to resolve to the following 2 IP addresses.

February 9, 2016

February 9, 2016

File downloads found at URLs served by tomdownload.net.

1 / 68      (PUP)

2 / 68      (PUP)

1 / 68      (PUP)

2 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (Malware)

10 / 68    (PUP)

1 / 68      (Malware)

10 / 68    (PUP)

URL:
http://tomdownload.net/

Title:
“TomDownload -”

SSL certificate subject:
CN=sni26609.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx (PHP/5.4.30)