d.provideodownloader.com

Data Beat Solutions, LLC  (via a Proxy Registrant)

Domain Information

The domain d.provideodownloader.com is registered by proxy through GODADDY.COM, LLC and was originally registered in June of 2011. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Seattle, Washington within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below). The domain is associated with the publisher Data Beat Solutions, LLC who is located in San Diego, California in the United States.
Registrar:
GODADDY.COM, LLC

Server location:
Washington, United States (US)

Create date:
Monday, June 6, 2011

Expires date:
Sunday, January 1, 2017

Updated date:
Saturday, January 2, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.DataBeatSolutions.F, PUP.Injekt.DataBeat.Installer (M)
100.00%

Bkav FE
W32.Clodd67.Trojan
50.00%

McAfee
Artemis!9A2E058F3554
50.00%

Malwarebytes
PUP.Optional.SearchDonkey.A
50.00%

Norman
Malware
50.00%

Trend Micro House Call
TROJ_GEN.F47V1011
50.00%

avast!
Win32:BHO-AMO [PUP]
50.00%

Dr.Web
Adware.Plugin.128
50.00%

VIPRE Antivirus
SearchDonkey
50.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
50.00%

ESET NOD32
Win32/ExFriendAlert (variant)
50.00%

The domain d.provideodownloader.com has been seen to resolve to the following 16 IP addresses.

server-52-84-125-219.iad16.r.cloudfront.net
June 3, 2016

server-52-84-125-134.iad16.r.cloudfront.net
June 3, 2016

server-52-84-125-77.iad16.r.cloudfront.net
June 3, 2016

server-52-84-125-61.iad16.r.cloudfront.net
June 3, 2016

server-52-84-125-38.iad16.r.cloudfront.net
June 3, 2016

server-52-84-125-12.iad16.r.cloudfront.net
June 3, 2016

server-52-84-125-246.iad16.r.cloudfront.net
June 3, 2016

server-52-84-125-226.iad16.r.cloudfront.net
June 3, 2016

server-52-85-131-165.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-100.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-94.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-70.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-57.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-34.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-21.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-218.iad53.r.cloudfront.net
April 16, 2016

File downloads found at URLs served by d.provideodownloader.com.

1 / 68      (Adware)

11 / 68    (Adware)

The following 16 files have been seen to comunicate with d.provideodownloader.com in live environments.

 
Latest 20 of 38 files

URL:
http://d.provideodownloader.com/

Network:
Amazon Cloudfront

Web server:
AmazonS3