dll513.yourfdownloader.net

Whois Privacy Corp.

Domain Information

The domain dll513.yourfdownloader.net registered by Whois Privacy Corp. was initially registered in January of 2015 through TLD REGISTRAR SOLUTIONS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Registrar:
TLD REGISTRAR SOLUTIONS LTD

Server location:
Quebec, Canada (CA)

Create date:
Tuesday, January 27, 2015

Expires date:
Friday, January 27, 2017

Updated date:
Thursday, January 28, 2016

Scanner detections:
Detections  (95% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Via Advertising, PUP.Task.Via Advertising, PUP.Bundler.Via Advertising, PUP.Via Advertising.Bundler, PUP.Via Advertising.ViaAdvertisingGroup.Bundler (M), Threat.Win.Reputation.IMP, PUP.Via Advertising.ViaAdver.Bundler (M), PUP.Via Advertising.Supers.Bundler (M), PUP.Via Advertising.RomirPro.Bundler (M), PUP.Via Advertising (M)
89.47%

Dr.Web
Adware.Downware.9685, Adware.Downware.9735, Threat.Undefined, Adware.Downware.10330
31.58%

avast!
Win32:Downloader-UEO [PUP], Win32:Dropper-gen [Drp], Win32:Malware-gen
31.58%

VIPRE Antivirus
Threat.4758264, Threat.4150696, Trojan.Win32.Generic, Via Advertising
31.58%

AVG
Generic, Generic_r, Adware Generic_r, Adware Generic_r.YX
31.58%

ESET NOD32
Win32/ExpressDownloader.K potentially unwanted application
28.95%

Avira AntiVirus
APPL/Downloader.Gen4, PUA/EDownloader.Gen
28.95%

Sophos
PUA 'Go For Files'
23.68%

K7 AntiVirus
Unwanted-Program , Trojan
18.42%

Comodo Security
Virus.Win32.Virut.CE, Application.Win32.ExpressDownloader.CA
18.42%

AhnLab V3 Security
Win-PUP/YourFileDownloader, PUP/Win32.YourFileDownloader
18.42%

Emsisoft Anti-Malware
Adware.Agent.PGP, Application.YourFileDownloader, Gen:Variant.Kazy.610076, Gen:Variant.Graftor.186945
15.79%

Lavasoft Ad-Aware
Adware.Agent.PGP, Application.YourFileDownloader.B, Gen:Variant.Kazy.610076, Gen:Variant.Graftor.186945
15.79%

MicroWorld eScan
Adware.Agent.PGP, Application.YourFileDownloader.B, Gen:Variant.Kazy.610076, Gen:Variant.Graftor.186945
15.79%

Bitdefender
Adware.Agent.PGP, Application.YourFileDownloader.B, Gen:Variant.Kazy.610076, Gen:Variant.Graftor.186945
13.16%

The domain dll513.yourfdownloader.net has been seen to resolve to the following 7 IP addresses.

June 4, 2016

June 3, 2016

ns513839.ip-167-114-156.net
April 15, 2016

ns1.ibspark.com
January 30, 2016

199.195.196.180.static.midphase.com
November 18, 2015

209.95.43.22.static.midphase.com
May 4, 2015

February 15, 2015

File downloads found at URLs served by dll513.yourfdownloader.net.

 
Latest 30 of 41 download URLs

The following 191 files have been seen to comunicate with dll513.yourfdownloader.net in live environments.

 
Latest 20 of 214 files

URL:
http://dll513.yourfdownloader.net/

Google Analytics:
UA-48689684

Title:
“yourfdownloader.net”

Web server:
nginx

30 of 618 related domains