helper.sf-download.com

Domain Privacy Service FBO Registrant.  (Proxy Registrant)

Domain Information

The domain helper.sf-download.com is registered by proxy through DOMAIN.COM, LLC and was originally registered in December of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Berlin, Berlin within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
DOMAIN.COM, LLC

Server location:
Berlin, Germany (DE)

Create date:
Thursday, December 17, 2015

Expires date:
Sunday, December 17, 2017

Updated date:
Thursday, December 17, 2015

ASN:
AS24940 HETZNER-AS Hetzner Online GmbH,DE

Root domain:

Scanner detections:
Detections  (73% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Magicbit.Savefrom.Meta (L), PUP.SaveForm.Optional.Installer.Meta (L), (M), PUP.SaveForm.Optional (L)
90.91%

ESET NOD32
Win32/Magicbit.C potentially unwanted application, Win32/Magicbit.D potentially unwanted application
18.18%

Bkav FE
W32.HfsAdware
9.09%

Malwarebytes
PUP.Optional.OpenCandy
9.09%

K7 AntiVirus
Unwanted-Program
9.09%

ESET NOD32
Win32/Magicbit.A potentially unwanted
9.09%

AVG
Generic
9.09%

The domain helper.sf-download.com has been seen to resolve to the following IP address.

static.155.42.243.136.clients.your-server.de
February 13, 2016

File downloads found at URLs served by helper.sf-download.com.

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

 
Latest 30 of 94 download URLs

The following 78 files have been seen to comunicate with helper.sf-download.com in live environments.

 
Latest 20 of 119 files

URL:
http://helper.sf-download.com/

Web server:
nginx (PHP/5.4.45)