cdn.frogdownload.com

Somoto Ltd.  (via a Proxy Registrant)

Domain Information

frogdownload.com is the file server that hosts adware bundlers for the FilesFrog.com service run by Somoto. The domain cdn.frogdownload.com is registered by proxy through GODADDY.COM, LLC and was originally registered in May of 2012. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below). The domain is associated with the publisher Somoto Ltd. who is located in Tel Aviv, Israel.
Registrar:
GODADDY.COM, LLC

Server location:
New York, United States (US)

Create date:
Sunday, May 20, 2012

Expires date:
Friday, May 20, 2016

Updated date:
Thursday, May 22, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.BetterInstaller.Somoto.J, PUP.Somoto.Bundler (M), PUP.Somoto (M)
98.00%

Malwarebytes
PUP.Optional.Somoto.A
8.00%

F-Prot
W32/SomotoBetterInstaller.A
8.00%

avast!
Win32:PUP-gen [PUP], Win32:Somoto-K [PUP]
8.00%

Clam AntiVirus
Adware.Somoto-1
8.00%

SUPERAntiSpyware
Adware.Somoto/Variant
8.00%

Sophos
Somoto BetterInstaller
8.00%

Comodo Security
Application.Win32.Somoto.A
8.00%

Dr.Web
Adware.Somoto.17
8.00%

VIPRE Antivirus
BetterInstaller
8.00%

Avira AntiVirus
APPL/Somoto.Gen2
8.00%

Vba32 AntiVirus
Downloader.Agent
8.00%

ESET NOD32
Win32/Somoto
8.00%

AVG
AdInstaller.Somoto
8.00%

K7 AntiVirus
Unwanted-Program
6.00%

The domain cdn.frogdownload.com has been seen to resolve to the following 909 IP addresses.

server-52-84-125-192.iad16.r.cloudfront.net
September 16, 2016

server-52-84-125-230.iad16.r.cloudfront.net
September 16, 2016

server-52-84-125-225.iad16.r.cloudfront.net
September 16, 2016

server-54-230-193-44.iad53.r.cloudfront.net
September 14, 2016

server-54-230-193-183.iad53.r.cloudfront.net
September 13, 2016

server-54-230-193-119.iad53.r.cloudfront.net
September 13, 2016

server-54-230-193-112.iad53.r.cloudfront.net
September 13, 2016

server-54-230-193-70.iad53.r.cloudfront.net
September 13, 2016

server-54-230-193-64.iad53.r.cloudfront.net
September 13, 2016

server-54-230-193-9.iad53.r.cloudfront.net
September 13, 2016

server-54-230-193-198.iad53.r.cloudfront.net
September 13, 2016

server-52-84-125-6.iad16.r.cloudfront.net
September 13, 2016

server-52-84-125-9.iad16.r.cloudfront.net
September 13, 2016

server-52-84-125-199.iad16.r.cloudfront.net
September 13, 2016

server-52-84-125-113.iad16.r.cloudfront.net
September 13, 2016

server-52-84-125-41.iad16.r.cloudfront.net
September 13, 2016

server-52-84-125-36.iad16.r.cloudfront.net
September 13, 2016

server-54-230-193-160.iad53.r.cloudfront.net
September 3, 2016

server-54-230-193-93.iad53.r.cloudfront.net
September 3, 2016

server-54-230-193-33.iad53.r.cloudfront.net
September 3, 2016

server-54-230-193-248.iad53.r.cloudfront.net
September 3, 2016

server-54-230-193-212.iad53.r.cloudfront.net
September 3, 2016

server-52-84-125-47.iad16.r.cloudfront.net
September 1, 2016

server-52-84-125-117.iad16.r.cloudfront.net
August 30, 2016

server-54-192-19-113.iad12.r.cloudfront.net
August 27, 2016

server-54-192-19-110.iad12.r.cloudfront.net
August 27, 2016

server-54-192-19-77.iad12.r.cloudfront.net
August 27, 2016

server-54-192-19-35.iad12.r.cloudfront.net
August 27, 2016

server-54-230-193-51.iad53.r.cloudfront.net
August 26, 2016

server-52-84-125-190.iad16.r.cloudfront.net
August 26, 2016

 
Showing 30 of 909 IP Addresses

File downloads found at URLs served by cdn.frogdownload.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

15 / 68    (Adware)

1 / 68      (Adware)

 
Latest 30 of 821 download URLs

The following 941 files have been seen to comunicate with cdn.frogdownload.com in live environments.

 
Latest 20 of 2,882 files

URL:
http://cdn.frogdownload.com/

Network:
Amazon Cloudfront

Web server:
nginx