pfn.dlgvit.com

Only contact by email, all postal mail will be rejected  (Proxy Registrant)

Domain Information

The domain pfn.dlgvit.com is registered by proxy through SOLUCIONES CORPORATIVAS IP, SL and was originally registered in May of 2015. Currently this domain has been known to host various forms of malware. The hosted servers are located in Roubaix, Nord-Pas-De-Calais within France which resides on the RIPE Network Coordination Centre network.
Registrar:
SOLUCIONES CORPORATIVAS IP, SL

Server location:
Nord-Pas-De-Calais, France (FR)

Create date:
Thursday, May 21, 2015

Expires date:
Sunday, May 21, 2017

Updated date:
Thursday, April 14, 2016

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Malware distribution  (75% detected)

Scan engine
Details
Detections

Reason Heuristics
(M), PUP.Optional.DsNET.Atube.Installer.Meta
100.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
33.33%

ESET NOD32
Win32/Bundled.Toolbar.Ask.G potentially unsafe (variant)
33.33%

Dr.Web
Adware.Toolbar.282
33.33%

The domain pfn.dlgvit.com has been seen to resolve to the following IP address.

ns3014179.ip-149-202-192.eu
April 14, 2016

File downloads found at URLs served by pfn.dlgvit.com.

0 / 68
http://pfn.dlgvit.com/crawled_soft/2/2/.../228488-676828-adobe-flash-player.exe  (install_flashplayer15x32ax_gtbd_chrd_dn_aaa_aih.exe)

2 / 68      (Malware)

1 / 68      (Malware)

The following 40 files have been seen to comunicate with pfn.dlgvit.com in live environments.

 
Latest 20 of 41 files

URL:
http://pfn.dlgvit.com/

Web server:
nginx

30 of 39 related domains