dfs.ezdownloadpro.info

Rafael Leviev

Domain Information

This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Munich, Bayern within Germany which resides on the RIPE Network Coordination Centre network. The domain is associated with the publisher Rafael Leviev who is located in Shfela, Israel.
Registrar:
1API GmbH

Server location:
Bayern, Germany (DE)

ASN:
AS61969 TEAMINTERNET-AS Team Internet AG,DE

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP
100.00%

ESET NOD32
Win32/Adware.MultiPlug.FC application, Win32/Adware.MultiPlug.FA application
72.73%

F-Secure
Gen:Variant.Adware.Mikey.8516
63.64%

Dr.Web
Trojan.Crossrider1.20349, Trojan.DownLoader12.30773, Trojan.Crossrider1.20043, Trojan.Crossrider1.20145
63.64%

Lavasoft Ad-Aware
Gen:Variant.Adware.Mikey.8516
63.64%

McAfee
Program.MultiPlug-FWG
63.64%

Emsisoft Anti-Malware
Gen:Variant.Adware.Mikey.8516
63.64%

Sophos
PUA 'MultiPlug' (of type Adware)
63.64%

MicroWorld eScan
Adware.MultiPlug.FW, Gen:Variant.Adware.Mikey.8516
63.64%

Malwarebytes
PUP.Optional.Unizeto
63.64%

K7 AntiVirus
Unwanted-Program
63.64%

F-Prot
W32/S-c684d5f4, W32/S-4ef98cc5, W32/MultiPlug.H.gen
63.64%

Bitdefender
Adware.MultiPlug.FW, Gen:Variant.Adware.Mikey.8516
63.64%

NANO AntiVirus
Riskware.Win32.MultiPlug.dojkve, Riskware.Win32.MultiPlug.dojkvm, Riskware.Win32.MultiPlug.dohysv, Riskware.Win32.MultiPlug.dogrkr
63.64%

Comodo Security
Application.Win32.AdWare.MultiPlug.VA
63.64%

The domain dfs.ezdownloadpro.info has been seen to resolve to the following 2 IP addresses.

August 8, 2016

February 27, 2016

File downloads found at URLs served by dfs.ezdownloadpro.info.

URL:
http://dfs.ezdownloadpro.info/

Title:
“ezdownloadpro.info”

Web server:
nginx