The domain hd-plugin.com is registered by proxy through EASTEND DOMAINS, LLC and was originally registered in April of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrant:
PERFECT PRIVACY, LLC
Registrar:
EASTEND DOMAINS, LLC
Server location:
Arizona, United States (US)
Create date:
Tuesday, April 26, 2016
Expires date:
Wednesday, April 26, 2017
Updated date:
Tuesday, April 26, 2016
ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US
Scanner detections:
Detections (90% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.VASSANAKONGSOONGNERN.Q, PUP.VASSANAKONGSOONGNERN.K, PUP.CHUTCHAIKIEWNOY.Q, PUP.VASSANAKONGSOONGNERN.Q, PUP.KanchanaKhiandee.Q, PUP.CoolMirage.VASSANAKONGSOONGNERN.Installer (M), PUP.ThitimaPhiwsawang.Installer (M)
100.00%
VIPRE Antivirus
CoolMirage Ltd, Trojan.Win32.Generic
57.89%
Kaspersky
not-a-virus:AdWare.NSIS.Yontoo, not-a-virus:Downloader.Win32.TornTV
52.63%
Dr.Web
Adware.Downware.8319, Adware.Yontoo.54
52.63%
Sophos
CoolMirage, Kanchana Khiandee adware, Generic PUA LE, Generic PUA GK
47.37%
K7 AntiVirus
Adware , Trojan-Downloader , Riskware
42.11%
McAfee
Artemis!853654972DB5, Artemis!F77A44832E45, Artemis!1009B0450E65, Artemis!71BF39324628, Artemis!0B50402C066A, Artemis!DA787EF9DE27
31.58%
Baidu Antivirus
Adware.NSIS.Yontoo, Hacktool.Win32.TornTV
26.32%
ESET NOD32
NSIS/TrojanDownloader.Adload, NSIS/TrojanDownloader.Adload.AC
26.32%
Avira AntiVirus
Adware/Yontoo.71608, Adware/Yontoo.71616, Adware/Yontoo.80336, Adware/Yontoo.77224
21.05%
Trend Micro House Call
Suspicious_GEN.F47V1113, Suspici.8B120837, TROJ_GEN.R02SC0EKD14, Suspicious_GEN.F47V0130
21.05%
avast!
Win32:Rootkit-gen [Rtk], Win32:Adware-gen [Adw]
15.79%
Panda Antivirus
Trj/Chgt.K, Generic Suspicious
15.79%
G Data
Win32.Trojan.Agent.R8I40Q, Win32.Application.Agent.3LIORS
10.53%
The domain hd-plugin.com has been seen to resolve to the following 15 IP addresses.
ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
May 5, 2016
ip-50-63-202-41.ip.secureserver.net
February 12, 2016
ec2-54-246-121-152.eu-west-1.compute.amazonaws.com
November 19, 2015
ec2-54-246-120-161.eu-west-1.compute.amazonaws.com
July 16, 2015
ec2-176-34-107-151.eu-west-1.compute.amazonaws.com
June 18, 2015
ec2-54-217-233-226.eu-west-1.compute.amazonaws.com
May 3, 2015
ec2-54-228-201-246.eu-west-1.compute.amazonaws.com
May 3, 2015
ec2-184-169-157-32.us-west-1.compute.amazonaws.com
November 2, 2014
ec2-50-18-168-176.us-west-1.compute.amazonaws.com
October 24, 2014
ec2-54-241-253-59.us-west-1.compute.amazonaws.com
September 2, 2014
ec2-50-18-104-209.us-west-1.compute.amazonaws.com
August 16, 2014
ec2-184-169-175-49.us-west-1.compute.amazonaws.com
May 14, 2014
File downloads found at URLs served by hd-plugin.com.
Latest 30 of 138 download URLs
The following 231 files have been seen to comunicate with hd-plugin.com in live environments.
Subdomains
URL:
http://hd-plugin.com/
Google Analytics:
UA-48689684
Related Domains
30 of 618 related domains