d.websteroidsapp.com

Parallel Lines Development, LLC  (via a Proxy Registrant)

Domain Information

The domain d.websteroidsapp.com is registered by proxy through GODADDY.COM, LLC and was originally registered in July of 2013. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below). The domain is associated with the publisher Parallel Lines Development, LLC who is located in San Diego, California in the United States.
Remove Malware from d.websteroidsapp.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Monday, July 01, 2013

Expires date:
Wednesday, July 01, 2015

Updated date:
Monday, June 23, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

McAfee
Artemis!85CC6475212A, Artemis!189E1F06D82C
100.00%

Malwarebytes
PUP.Optional.WebSteroids.A, PUP.Optional.Websteroids.A
100.00%

K7 Gateway Antivirus
Unwanted-Program , Adware
100.00%

K7 AntiVirus
Unwanted-Program , Adware
100.00%

Trend Micro House Call
TROJ_GEN.F47V0326, Suspicious_GEN.F47V0910
100.00%

Comodo Security
ApplicUnwnt
100.00%

Dr.Web
Adware.Plugin.128, Adware.Downware.8565
100.00%

VIPRE Antivirus
SearchDonkey, Injekt
100.00%

Avira AntiVirus
Adware/Agent.nur.15, ADWARE/Adware.Gen
100.00%

McAfee Web Gateway
Artemis!85CC6475212A
100.00%

Sophos
Search Donkey
100.00%

Antiy Labs AVL
Trojan/Win32.SGeneric
100.00%

ESET NOD32
MSIL/Adware.PullUpdate
100.00%

Fortinet FortiGate
Adware/PullUpdate
100.00%

Qihoo 360 Security
Win32/Trojan.Adware.988, HEUR/Malware.QVM10.Gen
100.00%

The domain d.websteroidsapp.com has been seen to resolve to the following 16 IP addresses.

server-54-230-19-214.iad12.r.cloudfront.net
November 1, 2014

server-54-230-19-102.iad12.r.cloudfront.net
November 1, 2014

server-54-230-18-211.iad12.r.cloudfront.net
November 1, 2014

server-54-230-18-206.iad12.r.cloudfront.net
November 1, 2014

server-54-230-18-78.iad12.r.cloudfront.net
November 1, 2014

server-54-230-17-99.iad12.r.cloudfront.net
November 1, 2014

server-54-230-16-62.iad12.r.cloudfront.net
November 1, 2014

server-54-230-19-242.iad12.r.cloudfront.net
November 1, 2014

server-204-246-169-253.jfk1.r.cloudfront.net
April 11, 2014

server-54-230-38-228.jfk1.r.cloudfront.net
April 11, 2014

server-54-230-36-21.jfk1.r.cloudfront.net
April 11, 2014

server-204-246-169-228.jfk1.r.cloudfront.net
April 11, 2014

server-54-230-37-188.jfk1.r.cloudfront.net
April 11, 2014

server-204-246-169-147.jfk1.r.cloudfront.net
April 11, 2014

server-54-230-39-77.jfk1.r.cloudfront.net
April 11, 2014

server-54-230-37-137.jfk1.r.cloudfront.net
April 11, 2014

File downloads found at URLs served by d.websteroidsapp.com.

18 / 68    (Adware)
http://d.websteroidsapp.com/Websteroids/334/.../Setup.exe  (189e1f06d82c0348e21aff05c731066c)

27 / 68    (Adware)
http://d.websteroidsapp.com/Websteroids/334/.../Setup.exe  (85cc6475212ab6f13b4b9eb7327c9155)

The following 2 files have been seen to comunicate with d.websteroidsapp.com in live environments.

URL:
http://d.websteroidsapp.com/

Network:
Amazon Cloudfront

Web server:
AmazonS3

Facebook:
Shares:  1

Statistics are for the previous month.

Remove Malware from d.websteroidsapp.com - Powered by Reason Core Security