download.savevid.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download.savevid.com is registered by proxy through GODADDY.COM, LLC and was originally registered in May of 2006. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Tel Aviv, Tel Aviv within Israel which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Tel Aviv, Israel (IL)

Create date:
Monday, May 22, 2006

Expires date:
Monday, May 22, 2017

Updated date:
Sunday, February 28, 2016

ASN:
AS6461 MFNX MFN - Metromedia Fiber Network

Root domain:

Scanner detections:
Detections  (95% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.BandooMedia.U, PUP.Optional.Installer.U, Win32.Generic.Installer.Bandoo.Meta, Win32.Generic.Bandoo.Installer.Meta
95.24%

Dr.Web
Adware.Bandoo.12, Adware.Bandoo.13, Adware.Bandoo.19, Adware.Bandoo.241, Adware.Bandoo.340, Win32.Sector.30
76.19%

Trend Micro House Call
TROJ_GEN.F47V1226, TROJ_GEN.F47V0923, Suspicious_GEN.F47V0619, Suspicious_GEN.F47V0817, Suspicious_GEN.F47V0731, Suspicious_GEN.F47V0909, TROJ_GEN.F47V0819
61.90%

AVG
MalSign.Generic, Adware Generic_r.VQ, Win32/Sality
42.86%

McAfee
Artemis!037F14B217AE, Artemis!194240C7C8FA, Artemis!7D6B85CA2E44, Artemis!51A6BE6D31C5, Trojan.Artemis!2D3C9D9FF30B, Artemis!C060CB6B6AAC
33.33%

Comodo Security
Application.Win32.Saveid.~BOO, Application.Win32.Bandoo.D
28.57%

Baidu Antivirus
Adware.Win32.SearchSuite, Adware.Win64.SearchSuite, PUA.Win32.SearchSuite
28.57%

Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite, Virus.Win32.Sality
23.81%

Panda Antivirus
Trj/Chgt.A, Trj/Chgt.B, Trj/Chgt.C, Trj/Chgt.F, PUP/iLivid
23.81%

Sophos
Generic PUA MF, Generic PUA DK, Virus 'Mal/Sality-D'
19.05%

IKARUS anti.virus
PUA.Bandoo
19.05%

Fortinet FortiGate
Riskware/Win64_SearchSuite, Riskware/SearchSuite
19.05%

Qihoo 360 Security
Win32/Virus.WebToolbar.49b
19.05%

Zillya! Antivirus
Adware.SearchSuite.Win64.154, Adware.Toolbar.Win32.436
19.05%

G Data
Win32.Adware.Bandoo, NSIS.Application.SearchSuite
19.05%

The domain download.savevid.com has been seen to resolve to the following 2 IP addresses.

94.31.0.25.IPYX-076665-ZYO.above.net
February 27, 2014

August 5, 2013

File downloads found at URLs served by download.savevid.com.

0 / 68
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

1 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

6 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bu.exe)

1 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

1 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

3 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bf.exe)

11 / 68    (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

9 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

16 / 68    (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

12 / 68    (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

2 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

13 / 68    (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

13 / 68    (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

4 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

16 / 68    (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

4 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

4 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

2 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bf.exe)

13 / 68    (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

3 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

3 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (savevidsetup-r0-n-bc.exe)

3 / 68      (PUP)
http://download.savevid.com/SavevidSetup.exe  (SavevidSetup-r0-n-bc.exe)

The following 15 files have been seen to comunicate with download.savevid.com in live environments.

URL:
http://download.savevid.com/

Web server:
Apache