files7.downloadster.org

Downloadster

Domain Information

downloadster distributes apps with its download manager which bundles adware toolbars such as Babylon and Rally as well as other potentially unwanted software. "We're able to offer free software because we are advertiser supported. When you download software, it gives our advertisers a chance to speak to you. ALL OFFERS ARE OPTIONAL. Users may be offered to change their browser homepage during install." This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Beaumaris, Victoria within Australia which resides on the Asia Pacific Network Information Centre network. The domain is associated with the publisher Downloadster who is located in SAN FRANCISCO, California in the United States.
Registrar:
Ulysses S. Grant, LLC

Server location:
Victoria, Australia (AU)

ASN:
AS133618 TRELLIAN-AS-AP Trellian Pty. Limited,AU

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.BulletMedia.U, PUP.Installer.Downloadster.U, Threat.Installer.BulletMedia, PUP.BulletMedia.Installer (M), PUP.Adlogica.Downloadster.Bundler (M), PUP.BulletMe.Installer (M), PUP (M), PUP.DownloadAdmin.Bundler (M)
97.92%

VIPRE Antivirus
Threat.4783369, DownloadAdmin, Threat.4150696
18.75%

Dr.Web
Adware.Downware.2220, Adware.Downware.644, Trojan.Vittalia.47, Trojan.Vittalia.81
18.75%

Sophos
PUA 'Download Admin'
14.58%

avast!
Adware-BIB [PUP], PUP-gen [PUP], DownloadAdmin-K [PUP], Win32:Adware-BIB [PUP]
12.50%

AVG
Adware Skodna.Bundle.AU, Generic
12.50%

Malwarebytes
PUP.DownloadAdmin
12.50%

NANO AntiVirus
Riskware.Nsis.Downware.dlgjls, Trojan.Win32.Downware.bwdcbn, Trojan.Win32.Downware.crgjbr
12.50%

F-Secure
Adware:W32/WebInstallBundle
10.42%

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application
10.42%

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
10.42%

herdProtect (fuzzy)
a variant of c56d217485d7e053e10dbcbf3e466c95ec17e8d1, a variant of 16d2c4e639751971e5051ec02b76484b2df048cb, a variant of f109bafab564f64daf1d06387d6756e9f98c9bf9
10.42%

McAfee
Artemis!5D46A7DCDBF5, Artemis!27C9F55AE7E3, Artemis!B351F18907F8
8.33%

Trend Micro House Call
TROJ_GEN.F47V0702, TROJ_GEN.F47V0223, TROJ_GEN.F47V0824
8.33%

Comodo Security
Application.Win32.DownloadAdmin.ANGL, Application.Win32.DownloadAdmin.G
6.25%

The domain files7.downloadster.org has been seen to resolve to the following 6 IP addresses.

lb-182-244.above.com
February 28, 2016

ip-184-168-221-37.ip.secureserver.net
December 19, 2015

50.22.63.140-static.reverse.softlayer.com
January 26, 2015

50.22.63.138-static.reverse.softlayer.com
January 26, 2015

50.97.63.217-static.reverse.softlayer.com
August 7, 2014

108.168.160.45-static.reverse.softlayer.com
August 7, 2014

File downloads found at URLs served by files7.downloadster.org.

1 / 68      (Adware)
http://files7.downloadster.org/dl?bc=30190  (vlcmediaplayer-setup.exe)

1 / 68      (Adware)

1 / 68      (Adware)

The following 249 files have been seen to comunicate with files7.downloadster.org in live environments.

 
Latest 20 of 335 files

URL:
http://files7.downloadster.org/

Title:
“downloadster.org”

Web server:
Apache