dlp.download-21.com

Whois Privacy Protection Service, Inc.  (Proxy Registrant)

Domain Information

The domain dlp.download-21.com is registered by proxy through NAME.COM, INC. and was originally registered in August of 2011. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
NAME.COM, INC.

Server location:
Oregon, United States (US)

Create date:
Thursday, August 11, 2011

Expires date:
Thursday, August 11, 2016

Updated date:
Friday, March 6, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.tuguusl.F, PUP.TuguuSL.F, PUP.Installer.TuguuSL.F, PUP.Tuguu.Bundler (M)
100.00%

Malwarebytes
PUP.Optional.DomaIQ, PUP.Optional.BundleInstaller.A
83.33%

K7 AntiVirus
Unwanted-Program
83.33%

avast!
Win32:Installer-U [PUP], Installer-AE [PUP], PUP-gen [PUP]
83.33%

Sophos
DomainIQ pay-per install
83.33%

Comodo Security
Application.Win32.DomaIQ.PUP, Application.Win32.DomaIQ.S, Application.Win32.DomaIQ.Q
83.33%

Dr.Web
Adware.Downware.2630, Trojan.Packed.24553
83.33%

VIPRE Antivirus
DomaIQ, Threat.4150696, Threat.4783235
83.33%

Avira AntiVirus
APPL/DomaIQ.Gen, APPL/DomaIQ.Gen7
83.33%

Panda Antivirus
PUP/MultiToolbar.A
83.33%

AVG
DomaIQ, Adware AdLoad.B, Adware DomaIQ
83.33%

MicroWorld eScan
Gen:Variant.Adware.Graftor.139070, Adware.DomaIQ.H, Application.Bundler.DomaIQ.Q
83.33%

Agnitum Outpost
PUA.DomaIQ
83.33%

Bitdefender
Gen:Variant.Adware.Graftor.139070, Adware.DomaIQ.H, Application.Bundler.DomaIQ.Q
83.33%

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.139070, Adware.DomaIQ.H, Application.Bundler.DomaIQ.Q
83.33%

The domain dlp.download-21.com has been seen to resolve to the following 7 IP addresses.

ec2-52-24-184-55.us-west-2.compute.amazonaws.com
February 16, 2016

ec2-52-24-189-16.us-west-2.compute.amazonaws.com
February 16, 2016

December 1, 2014

September 3, 2014

September 3, 2014

April 16, 2014

April 16, 2014

File downloads found at URLs served by dlp.download-21.com.

1 / 68      (Adware)

30 / 68    (Adware)

20 / 68    (Adware)

20 / 68    (Adware)

URL:
http://dlp.download-21.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx