dl.downloadmr.com

FIRSERIA, S.L.  (via a Proxy Registrant)

Domain Information

The domain dl.downloadmr.com is registered by proxy through GODADDY.COM, LLC and was originally registered in December of 2010. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States. The domain uses the Amazon Web Services (AWS) cloud computing platform. The domain is associated with the publisher FIRSERIA, S.L. who is located in Badalona, Barcelona in Spain.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Monday, December 20, 2010

Expires date:
Tuesday, December 20, 2016

Updated date:
Saturday, April 25, 2015

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SolimbaAplicacionesSL.BB, PUP.SolimbaAplicacionesSL.P, PUP.SolimbaAplicacionesSL.M, PUP.Solimba.SolimbaAplicaciones.Bundler (M), PUP.Solimba.SolimbaA.Bundler (M), PUP.Solimba (M)
100.00%

VIPRE Antivirus
Threat.4782980, DownloadMR
16.67%

Dr.Web
Adware.Downware.83, Adware.Downware.798
16.67%

Emsisoft Anti-Malware
Gen:Variant.Adware.Solimba, Riskware.Win32.Wrapper.Solimba.AMN
16.67%

Malwarebytes
Trojan.Repacked, PUP.BundleInstaller.DMR, PUP.Offerware
16.67%

Sophos
Solimba Installer, Generic PUA IL
16.67%

Avira AntiVirus
APPL/Solimba.Gen5, Adware/Solimba.1.44
16.67%

Fortinet FortiGate
Adware/Solimba, Adware/Fam.NB, W32/PasswordProtectedEXE
16.67%

avast!
Solimba-D [PUP], MSIL:Solimba-F [PUP], Win32:PUP-gen [PUP], Win32:Solimba-D [PUP]
14.29%

F-Prot
W32/Solimba.A.gen
14.29%

MicroWorld eScan
Gen:Variant.Adware.Solimba.1
14.29%

NANO AntiVirus
Riskware.Win32.Solimba.xmvyy, Riskware.Win32..bdazvw, Riskware.Win32.Generic.bdazvw, Riskware.Win32.Downware.mqimt
14.29%

Bitdefender
Gen:Variant.Adware.Solimba.1
14.29%

F-Secure
Gen:Variant.Adware.Solimba.1, Adware.Solimba.A
14.29%

G Data
Gen:Variant.Adware.Solimba
14.29%

The domain dl.downloadmr.com has been seen to resolve to the following 28 IP addresses.

ec2-52-200-154-151.compute-1.amazonaws.com
June 2, 2016

ec2-54-236-168-240.compute-1.amazonaws.com
June 2, 2016

ec2-52-20-84-208.compute-1.amazonaws.com
May 28, 2016

ec2-52-202-205-175.compute-1.amazonaws.com
May 28, 2016

ec2-52-200-161-90.compute-1.amazonaws.com
May 22, 2016

ec2-52-201-21-3.compute-1.amazonaws.com
May 22, 2016

ec2-52-201-162-61.compute-1.amazonaws.com
May 19, 2016

ec2-52-201-40-16.compute-1.amazonaws.com
May 19, 2016

ec2-54-174-26-166.compute-1.amazonaws.com
April 17, 2016

ec2-52-201-143-40.compute-1.amazonaws.com
April 17, 2016

ec2-52-0-162-217.compute-1.amazonaws.com
April 3, 2016

ec2-54-175-137-158.compute-1.amazonaws.com
April 3, 2016

ec2-52-22-236-126.compute-1.amazonaws.com
February 10, 2016

ec2-52-0-64-164.compute-1.amazonaws.com
February 10, 2016

ec2-52-72-100-87.compute-1.amazonaws.com
January 28, 2016

ec2-52-72-129-35.compute-1.amazonaws.com
January 28, 2016

ec2-52-21-228-76.compute-1.amazonaws.com
January 27, 2016

ec2-54-88-99-109.compute-1.amazonaws.com
January 27, 2016

ec2-52-22-142-187.compute-1.amazonaws.com
December 26, 2015

ec2-52-21-174-21.compute-1.amazonaws.com
December 26, 2015

ec2-52-22-167-224.compute-1.amazonaws.com
December 16, 2015

ec2-52-22-114-143.compute-1.amazonaws.com
December 16, 2015

ec2-52-22-131-32.compute-1.amazonaws.com
December 4, 2015

ec2-54-84-28-193.compute-1.amazonaws.com
December 4, 2015

ec2-54-165-65-72.compute-1.amazonaws.com
August 11, 2015

ec2-52-6-62-98.compute-1.amazonaws.com
August 11, 2015

ec2-23-23-183-126.compute-1.amazonaws.com
September 27, 2014

ec2-23-23-236-103.compute-1.amazonaws.com
September 27, 2014

File downloads found at URLs served by dl.downloadmr.com.

1 / 68      (Adware)
http://dl.downloadmr.com/.../cars-2.exe  (8f220e2c6f0de5789b8550f5b0404b9f)

1 / 68      (Adware)
http://dl.downloadmr.com/.../OvO.exe  (862e3c65f099cfa7d66678a512619689)

1 / 68      (Adware)
http://dl.downloadmr.com/.../teamviewer.exe  (34ab7c79fe28da157d64c29badd8316f)

1 / 68      (Adware)
http://dl.downloadmr.com/.../emule-phoenix-b.exe  (52a25912f4e08660b057db29877da939)

1 / 68      (Adware)
http://dl.downloadmr.com/.../club-dj-pro.exe  (10d3bd371f503ee08de626381f8800f1)

1 / 68      (Adware)
http://dl.downloadmr.com/.../deejaysystem.exe  (621e1a3ec298220814b6a49f310c166e)

1 / 68      (Adware)
http://dl.downloadmr.com/.../pcdj-dex.exe  (4d29bc3d2959b9109e9f99b5ac90668d)

1 / 68      (Adware)
http://dl.downloadmr.com/2.1.816/.../left-4-dead-2.exe  (33de22d2736a79cb3efb0a7520dfff96)

26 / 68    (Adware)
http://dl.downloadmr.com/.../J DOWNLOADER.exe  (02c4034baec4687ea546518548c7096b)

1 / 68      (Adware)
http://dl.downloadmr.com/.../Mediaget.exe  (197e009504f905b87e6abac022de8bb8)

1 / 68      (Adware)
http://dl.downloadmr.com/.../hair-master.exe  (51f6565f6a2010a9de6f0c4d756d3bd8)

1 / 68      (Adware)
http://dl.downloadmr.com/.../Windows Live Messenger.exe  (7d5705ba5cb7ba7f37e0cc51c23dc436)

1 / 68      (Adware)
http://dl.downloadmr.com/.../cyberfoot.exe  (85f2a58f5481bd0e5c0453ea022b6232)

1 / 68      (Adware)
http://dl.downloadmr.com/.../AVS Media Player.exe  (8dd052d8117d559053e82c5b638302a8)

1 / 68      (Adware)
http://dl.downloadmr.com/.../moon-3d-screensaver.exe  (d6b9daa89f25689f29481e4f58034a8d)

1 / 68      (Adware)
http://dl.downloadmr.com/.../mspacpc.exe  (c8d009a21ac347d22899063d93fe069e)

1 / 68      (Adware)
http://dl.downloadmr.com/.../macromedia-freehand-mx.exe  (dc6dc684d3b18f1a221892d4871d8125)

29 / 68    (Adware)
http://dl.downloadmr.com/.../AVS_Media_Player.exe  (eb0d4bdbb2baa4a36434ddbe2781e027)

1 / 68      (Adware)
http://dl.downloadmr.com/.../S4 League.exe  (bb3b5cb8086fa3fb455c1b590c5812df)

1 / 68      (Adware)
http://dl.downloadmr.com/.../VLC Media Player.exe  (42c8749ec90390e740acc2cdec664252)

1 / 68      (Adware)
http://dl.downloadmr.com/.../AVS Media Player.exe  (61b8e072480e5e89c888ee8669c4443b)

1 / 68      (Adware)
http://dl.downloadmr.com/2.1.147/.../Google Chrome.exe  (1b2eda16b94388fdd76fe7dfb0f5caa8)

1 / 68      (Adware)
http://dl.downloadmr.com/.../audi-r8-gold.exe  (99094a54f78b5719459d1453ae197115)

1 / 68      (Adware)
http://dl.downloadmr.com/.../dj-audio-editor.exe  (79d16f1255401c705a25e95847de8ab4)

1 / 68      (Adware)
http://dl.downloadmr.com/.../sound-editor-deluxe.exe  (9f247476ab3c0ba14f90bc00159ce11e)

1 / 68      (Adware)
http://dl.downloadmr.com/.../mi-primer-amigo.exe  (b1e2783728f2c5c221a685f91ee73eed)

1 / 68      (Adware)
http://dl.downloadmr.com/.../MathType.exe  (e0122fc17c8fa0cf24535117a1d4cc40)

1 / 68      (Adware)
http://dl.downloadmr.com/.../zararadio.exe  (6e59f074dfc5a935c26a7cade1ef4294)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.downloadmr.com/.../brick-break.exe  (5d5dcb415e29fe8ae8373225694c7c1e)

 
Latest 30 of 42 download URLs

The following file have been seen to comunicate with dl.downloadmr.com in live environments.

URL:
http://dl.downloadmr.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx