dlf.searchfiles.freedirectdownload.ru

Private Person  (Proxy Registrant)

Domain Information

The domain dlf.searchfiles.freedirectdownload.ru is registered by proxy through REGRU-RU and was originally registered in April of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-RU

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Monday, April 28, 2014

Expires date:
Thursday, April 28, 2016

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

AhnLab V3 Security
PUP/Win32.Amonetiz
100.00%

AVG
Generic
100.00%

Reason Heuristics
PUP.Installer.AMGRUP.CC
100.00%

avast!
Win32:Adware-gen [Adw]
100.00%

Emsisoft Anti-Malware
Gen:Variant.Adware.Netfilter
100.00%

F-Secure
Gen:Variant.Adware.Netfilter.2
100.00%

ESET NOD32
Win32/Amonetize.CK potentially unwanted application
100.00%

Lavasoft Ad-Aware
Gen:Variant.Adware.Netfilter.2
100.00%

McAfee
Trojan.Artemis!DE732793E0EA
100.00%

Norman
Gen:Variant.Adware.Netfilter.2
100.00%

MicroWorld eScan
Gen:Variant.Adware.Netfilter.2
100.00%

Agnitum Outpost
PUA.Amonetize
100.00%

Trend Micro House Call
TROJ_GEN.R08NH09LM14
100.00%

Bitdefender
Gen:Variant.Adware.Netfilter.2
100.00%

Avira AntiVirus
Adware/Amonetize.314368.1
100.00%

The domain dlf.searchfiles.freedirectdownload.ru has been seen to resolve to the following IP address.

unallocated.barefruit.co.uk
May 3, 2015

File downloads found at URLs served by dlf.searchfiles.freedirectdownload.ru.

The following 230 files have been seen to comunicate with dlf.searchfiles.freedirectdownload.ru in live environments.

 
Latest 20 of 230 files

URL:
http://dlf.searchfiles.freedirectdownload.ru/

Web server:
nginx/1.0.15