dl.filedeliverynow.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain dl.filedeliverynow.com is registered by proxy through GODADDY.COM, LLC and was originally registered in September of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Cambridge, Massachusetts within the United States which resides on the Akamai Technologies, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Massachusetts, United States (US)

Create date:
Friday, September 27, 2013

Expires date:
Saturday, September 27, 2014

Updated date:
Friday, September 27, 2013

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.PopelerSystemsl.T, PUP.Solimba.PopelerSystemsl.Installer (M), PUP.Solimba.Firseria.Bundler (M), PUP.Solimba.PopelerS.Installer (M), PUP.Solimba (M)
91.67%

Dr.Web
Trojan.DownLoader11.24441, Adware.Downware.9410
33.33%

Kaspersky
not-a-virus:Downloader.Win32.Morstar
33.33%

AVG
Generic, Adware BundleApp, Win32/Heur, Adware BundleApp.HA
33.33%

ESET NOD32
MSIL/Solimba.AH potentially unwanted application
25.00%

VIPRE Antivirus
Threat.4782980
16.67%

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Kazy.132995
16.67%

MicroWorld eScan
Gen:Variant.Application.Bundler.Kazy.132995
16.67%

Malwarebytes
.PUP.Optional.Solimba
16.67%

K7 AntiVirus
Unwanted-Program
16.67%

F-Prot
W32/A-a2151e6a
16.67%

Bitdefender
Gen:Variant.Application.Bundler.Kazy.132995
16.67%

NANO AntiVirus
Trojan.Win32.Morstar.delxop
16.67%

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Kazy.132995
16.67%

Sophos
Solimba Installer
16.67%

The domain dl.filedeliverynow.com has been seen to resolve to the following 2 IP addresses.

a23-0-160-16.deploy.static.akamaitechnologies.com
September 15, 2014

a23-0-160-51.deploy.static.akamaitechnologies.com
September 15, 2014

File downloads found at URLs served by dl.filedeliverynow.com.

1 / 68      (Adware)

7 / 68      (PUP)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.filedeliverynow.com/n/.../WhatsApp.exe  (96ecbc521272843d42c84674604e1dbd)

7 / 68      (PUP)

1 / 68      (Adware)
http://dl.filedeliverynow.com/n/3.1.22.17.1/.../EPSXE.exe  (7b2d4fd4554b2c6d66ab3250ab08b81e)

1 / 68      (Adware)

30 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

26 / 68    (Adware)

The following 26 files have been seen to comunicate with dl.filedeliverynow.com in live environments.

 
Latest 20 of 26 files

URL:
http://dl.filedeliverynow.com/

Web server:
nginx (PHP/5.5.16)