ds133.safegetportal.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain ds133.safegetportal.com is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Wednesday, October 23, 2013

Expires date:
Thursday, October 23, 2014

Updated date:
Tuesday, October 29, 2013

ASN:
AS16265 FIBERRING LeaseWeb B.V.,NL

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MaxigetLimited.G, PUP.New IT Limited.Maxiget.Bundler (M)
100.00%

Dr.Web
Adware.Downware.1613
50.00%

VIPRE Antivirus
Threat.4150696
50.00%

ESET NOD32
Win32/Maxiget.B potentially unwanted application
50.00%

SUPERAntiSpyware
Trojan.Agent/Gen-Graftor
50.00%

NANO AntiVirus
Trojan.Win32.Downware.cqujlm
50.00%

Agnitum Outpost
Trojan.Graftor
50.00%

Rising Antivirus
PE:PUF.4Shared!1.9C25
50.00%

Comodo Security
Application.Win32.GetFaster.A
50.00%

Avira AntiVirus
Adware/Graftor.123228.87
50.00%

Sophos
4Share Downloader
50.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
50.00%

AVG
Generic
50.00%

Malwarebytes
PUP.Optional.4Shared
50.00%

K7 AntiVirus
Unwanted-Program
50.00%

The domain ds133.safegetportal.com has been seen to resolve to the following 2 IP addresses.

hosted-by.leaseweb.com
May 23, 2016

hosted-by.leaseweb.com
July 3, 2014

File downloads found at URLs served by ds133.safegetportal.com.

1 / 68      (Adware)

16 / 68    (Adware)
http://ds133.safegetportal.com/.../1149_4.exe  (6064c2bd8e2a4f2156efd3487f702f33)

The following 18 files have been seen to comunicate with ds133.safegetportal.com in live environments.

 
Latest 20 of 22 files

URL:
http://ds133.safegetportal.com/

Google Analytics:
UA-41200419

Title:
“GetDownload CDN Network”

Web server:
Apache-Coyote/1.1

30 of 31 related domains