The domain download.cdn.savevid.com is registered by proxy through GODADDY.COM, LLC and was originally registered in May of 2006. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Limelight Networks, Inc. network.
Registrant:
Domains By Proxy, LLC
Registrar:
GODADDY.COM, LLC
Server location:
Virginia, United States (US)
Create date:
Monday, May 22, 2006
Expires date:
Monday, May 22, 2017
Updated date:
Sunday, February 28, 2016
ASN:
AS22822 LLNW-AS Limelight Networks, INC. proxy AS object
Scanner detections:
Detections (94% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Optional.Installer.BandooMedia.U, PUP.Optional.Installer.U, PUP.Optional.Installer.O, Win32.Generic.Installer.Bandoo.Meta
100.00%
Dr.Web
Adware.Bandoo.12, Adware.Bandoo.13, Adware.Bandoo.3, Adware.Bandoo.19, Adware.Bandoo.241, Adware.Bandoo.340
88.24%
Trend Micro House Call
TROJ_GEN.F47V1226, TROJ_GEN.F47V0923, Suspicious_GEN.F47V0619, Suspicious_GEN.F47V0817, Suspicious_GEN.F47V0731, Suspicious_GEN.F47V0909, TROJ_GEN.F47V0819
70.59%
AVG
MalSign.Generic, Bandoomed
47.06%
Baidu Antivirus
Adware.Win32.SearchSuite, Adware.Win64.SearchSuite, PUA.Win32.SearchSuite
35.29%
Comodo Security
Application.Win32.Saveid.~BOO, Application.Win32.Bandoo.D
29.41%
McAfee
Artemis!037F14B217AE, Artemis!194240C7C8FA, Artemis!7D6B85CA2E44, Artemis!51A6BE6D31C5, Artemis!C060CB6B6AAC
29.41%
Panda Antivirus
Trj/Chgt.A, Trj/Chgt.B, Trj/Chgt.C, Trj/Chgt.F, PUP/iLivid
29.41%
G Data
Win32.Adware.Bandoo, NSIS.Application.SearchSuite
29.41%
Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite
23.53%
IKARUS anti.virus
PUA.Bandoo
23.53%
Fortinet FortiGate
Riskware/Win64_SearchSuite, Riskware/SearchSuite
23.53%
Qihoo 360 Security
Win32/Virus.WebToolbar.49b
23.53%
Zillya! Antivirus
Adware.SearchSuite.Win64.154, Adware.Toolbar.Win32.436
23.53%
Sophos
Generic PUA MF, Generic PUA DK
17.65%
The domain download.cdn.savevid.com has been seen to resolve to the following 20 IP addresses.
cdn-208-111-161-254.iad.llnw.net
April 16, 2016
cdn-208-111-160-6.iad.llnw.net
April 16, 2016
a184-51-126-90.deploy.static.akamaitechnologies.com
February 17, 2016
a184-51-126-105.deploy.static.akamaitechnologies.com
February 17, 2016
a23-220-148-33.deploy.static.akamaitechnologies.com
February 8, 2016
a23-220-148-24.deploy.static.akamaitechnologies.com
February 8, 2016
a23-62-236-139.deploy.static.akamaitechnologies.com
May 5, 2015
a23-62-236-136.deploy.static.akamaitechnologies.com
May 5, 2015
a23-66-231-19.deploy.static.akamaitechnologies.com
May 4, 2015
a23-66-231-41.deploy.static.akamaitechnologies.com
May 4, 2015
a23-0-160-65.deploy.static.akamaitechnologies.com
November 3, 2014
a23-0-160-33.deploy.static.akamaitechnologies.com
September 5, 2014
a23-0-160-59.deploy.static.akamaitechnologies.com
September 5, 2014
a184-51-126-33.deploy.static.akamaitechnologies.com
September 5, 2014
a184-51-126-67.deploy.static.akamaitechnologies.com
September 5, 2014
a23-67-250-120.deploy.static.akamaitechnologies.com
May 23, 2014
a23-67-250-115.deploy.static.akamaitechnologies.com
April 16, 2014
a23-67-250-113.deploy.static.akamaitechnologies.com
April 16, 2014
a23-67-243-24.deploy.static.akamaitechnologies.com
August 5, 2013
File downloads found at URLs served by download.cdn.savevid.com.
The following 441 files have been seen to comunicate with download.cdn.savevid.com in live environments.
URL:
http://download.cdn.savevid.com/