d.websteroidsapp.com

Parallel Lines Development, LLC  (via a Proxy Registrant)

Domain Information

The domain d.websteroidsapp.com is registered by proxy through GODADDY.COM, LLC and was originally registered in July of 2013. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below). The domain is associated with the publisher Parallel Lines Development, LLC who is located in San Diego, California in the United States.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Monday, July 1, 2013

Expires date:
Friday, July 1, 2016

Updated date:
Thursday, July 2, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

McAfee
Artemis!E206F8289EB2, Artemis!85CC6475212A, Artemis!189E1F06D82C
100.00%

Trend Micro House Call
TROJ_GEN.F47V0324, TROJ_GEN.F47V0326, Suspicious_GEN.F47V0910
100.00%

Sophos
Search Donkey
100.00%

Dr.Web
Adware.Plugin.166, Adware.Plugin.128, Adware.Downware.8565
100.00%

VIPRE Antivirus
SearchDonkey, Injekt
100.00%

Reason Heuristics
PUP.Installer.CreativeIslandMedia.l, PUP.Installer.CreativeIslandMedia.F
100.00%

MicroWorld eScan
Adware.Agent.NUR, Dropped:Adware.Agent.NUR
66.67%

nProtect
Adware.Agent.NUR, Dropped:Adware.Agent.NUR
66.67%

Bitdefender
Adware.Agent.NUR, Dropped:Adware.Agent.NUR
66.67%

Lavasoft Ad-Aware
Adware.Agent.NUR, Dropped:Adware.Agent.NUR
66.67%

F-Secure
Adware.Agent.NUR
66.67%

Emsisoft Anti-Malware
Adware.Agent.NUR, Dropped:Adware.Agent.NUR
66.67%

G Data
Adware.Agent.NUR, Dropped:Adware.Agent.NUR
66.67%

Malwarebytes
PUP.Optional.WebSteroids.A, PUP.Optional.Websteroids.A
66.67%

K7 AntiVirus
Unwanted-Program , Adware
66.67%

The domain d.websteroidsapp.com has been seen to resolve to the following 24 IP addresses.

server-54-192-195-21.iad53.r.cloudfront.net
February 23, 2016

server-54-192-195-214.iad53.r.cloudfront.net
February 23, 2016

server-54-192-195-189.iad53.r.cloudfront.net
February 23, 2016

server-54-192-195-172.iad53.r.cloudfront.net
February 23, 2016

server-54-192-195-115.iad53.r.cloudfront.net
February 23, 2016

server-54-192-195-109.iad53.r.cloudfront.net
February 23, 2016

server-54-192-195-107.iad53.r.cloudfront.net
February 23, 2016

server-54-192-195-90.iad53.r.cloudfront.net
February 23, 2016

server-54-230-19-214.iad12.r.cloudfront.net
November 1, 2014

server-54-230-19-102.iad12.r.cloudfront.net
November 1, 2014

server-54-230-18-211.iad12.r.cloudfront.net
November 1, 2014

server-54-230-18-206.iad12.r.cloudfront.net
November 1, 2014

server-54-230-18-78.iad12.r.cloudfront.net
November 1, 2014

server-54-230-17-99.iad12.r.cloudfront.net
November 1, 2014

server-54-230-16-62.iad12.r.cloudfront.net
November 1, 2014

server-54-230-19-242.iad12.r.cloudfront.net
November 1, 2014

server-204-246-169-253.jfk1.r.cloudfront.net
April 11, 2014

server-54-230-38-228.jfk1.r.cloudfront.net
April 11, 2014

server-54-230-36-21.jfk1.r.cloudfront.net
April 11, 2014

server-204-246-169-228.jfk1.r.cloudfront.net
April 11, 2014

server-54-230-37-188.jfk1.r.cloudfront.net
April 11, 2014

server-204-246-169-147.jfk1.r.cloudfront.net
April 11, 2014

server-54-230-39-77.jfk1.r.cloudfront.net
April 11, 2014

server-54-230-37-137.jfk1.r.cloudfront.net
April 11, 2014

File downloads found at URLs served by d.websteroidsapp.com.

14 / 68    (Adware)
http://d.websteroidsapp.com/.../setup2.exe  (setup{45dc5386-83ab-4f3d-9985-a526441c3b19}.exe)

15 / 68    (Adware)
http://d.websteroidsapp.com/Websteroids/334/.../Setup.exe  (189e1f06d82c0348e21aff05c731066c)

23 / 68    (Adware)
http://d.websteroidsapp.com/Websteroids/334/.../Setup.exe  (85cc6475212ab6f13b4b9eb7327c9155)

The following 10 files have been seen to comunicate with d.websteroidsapp.com in live environments.

URL:
http://d.websteroidsapp.com/

Network:
Amazon Cloudfront

Web server:
AmazonS3

Facebook:
Shares:  1

Statistics are for the previous month.