dgn.distload.org

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain dgn.distload.org is registered by proxy through GoDaddy.com, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in San Jose, California within the United States which resides on the CDNetworks Inc. network.
Registrar:
GoDaddy.com, LLC

Server location:
California, United States (US)

ASN:
AS36408 CDNETWORKSUS-02 - CDNetworks Inc.,US

Root domain:

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Baidu Antivirus
Adware.Win32.Lyckriks, Adware.Win32.AddLyrics
87.10%

ESET NOD32
Win32/AdWare.AddLyrics.BJ, Win32/AdWare.AddLyrics.BO (variant), Win32/AdWare.AddLyrics.BR (variant), Win32/AdWare.AddLyrics.BW (variant)
70.97%

VIPRE Antivirus
Threat.5063086, Revizer, Trojan.Win32.Generic
67.74%

avast!
Dropper-gen [Drp], Win32:Dropper-gen [Drp], NSIS:Adware-PC [Adw], NSIS:Adware-PM [Adw], NSIS:Adware-PU [PUP], NSIS:Adware-QE [Adw]
61.29%

Malwarebytes
PUP.Optional.AdLyrics, PUP.Optional.Graftor, PUP.Optional.AddLyrics
58.06%

AVG
Generic_r, Adware Generic5.BOZF, Adware Generic5.BHCF, Adware Generic5.CIVV
48.39%

Lavasoft Ad-Aware
Gen:Variant.Graftor.152204, Gen:Variant.Adware.Graftor.155899, Gen:Variant.Adware.Graftor.153233, Application.Generic.802193
41.94%

F-Secure
Gen:Variant.Adware.Graftor.155899, Gen:Variant.Adware.Graftor.153233, Application.Generic.802193, Application.Generic.811190
38.71%

IKARUS anti.virus
PUA.AddLyrics, AdWare.AddLyrics, Win32.SuspectCrc
35.48%

Bitdefender
Gen:Variant.Graftor.146914, Gen:Variant.Graftor.152204, Gen:Variant.Adware.Graftor.155899, Gen:Variant.Adware.Graftor.153233, Gen:Variant.Adware.Graftor.162521
35.48%

G Data
Gen:Variant.Graftor.146914, Gen:Variant.Graftor.152204, Gen:Variant.Adware.Graftor.155899, Gen:Variant.Adware.Graftor.153233
35.48%

Qihoo 360 Security
HEUR/Malware.QVM06.Gen, Win32/Trojan.Dropper.c9f, Win32/Virus.Adware.0f6, Win32/Trojan.Multi.daf, HEUR/QVM42.0.Malware.Gen
32.26%

MicroWorld eScan
Gen:Variant.Graftor.146914, Gen:Variant.Adware.Graftor.155899, Gen:Variant.Adware.Graftor.153233, Application.Generic.802193, Application.Generic.811190, Gen:Variant.Adware.Graftor.162521, Dropped:Application.Generic.918253
29.03%

Kaspersky
not-a-virus:AdWare.Win32.Lyckriks, not-a-virus:AdWare.Win32.AddLyrics, UDS:DangerousObject.Multi.Generic
25.81%

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.155899, Gen:Variant.Adware.Graftor.153233, Gen:Variant.Adware.Graftor.162521
22.58%

The domain dgn.distload.org has been seen to resolve to the following 2 IP addresses.

September 15, 2014

September 15, 2014

File downloads found at URLs served by dgn.distload.org.

4 / 68      (PUP)
http://dgn.distload.org/apps/.../5555-1001_NewPlayer.exe  (7bae523fe2c751fabea732af89b39b26)

The following 17 files have been seen to comunicate with dgn.distload.org in live environments.

 
Latest 20 of 43 files