dl.desk1992get.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain dl.desk1992get.com is registered by proxy through GODADDY.COM, LLC and was originally registered in February of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Registrar:
GODADDY.COM, LLC

Server location:
Dublin City, Ireland (IE)

Create date:
Monday, February 1, 2016

Expires date:
Wednesday, February 1, 2017

Updated date:
Monday, February 1, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.POPELERSYSTEMSL.G, PUP.Solimba, Threat.Solimba.POPELERSYSTEM, PUP.Solimba.InvestenaConcept (M), PUP.Solimba.EilioDevelopments (M), PUP.Solimba.POPELERSYSTEM (M), PUP.Solimba.POPELERSYSTEM.Bundler (M), PUP.Solimba.POPELERS (M), PUP.Solimba.Investen (M), PUP.Solimba.Investen.Bundler (M), PUP.Solimba (M)
100.00%

avast!
Win32:Solimba-S [PUP]
6.82%

Dr.Web
Adware.Downware.9221, Trojan.DownLoader11.57090, Adware.Downware.10565, Adware.Downware.11048
6.82%

ESET NOD32
MSIL/Solimba.AK potentially unwanted application, MSIL/Solimba.AK.gen potentially unwanted application, Win32/TrojanDropper.Addrop.F trojan
6.82%

AVG
Adware BundleApp_r.AV, Adware BundleApp_r.AI, Popeler
6.82%

Emsisoft Anti-Malware
Trojan.Generic.12212911, Gen:Variant.Application.Kazy.525798, Gen:Variant.Kazy.604136
6.82%

VIPRE Antivirus
Threat.4782980
6.82%

MicroWorld eScan
Trojan.Generic.12212911, Gen:Variant.Application.Kazy.525798, Gen:Variant.Kazy.604136
6.82%

Kaspersky
not-a-virus:Downloader.Win32.Morstar
6.82%

Bitdefender
Trojan.Generic.12212911, Gen:Variant.Application.Kazy.525798, Gen:Variant.Application.Bundler.44
6.82%

NANO AntiVirus
Trojan.Win32.Morstar.djmjqv, Trojan.Win32.Morstar.dmuefk, Trojan.Win32.Morstar.dqwbnn
6.82%

Lavasoft Ad-Aware
Trojan.Generic.12212911, Gen:Variant.Application.Kazy.525798, Gen:Variant.Kazy.604136
6.82%

Avira AntiVirus
APPL/Firseria.Gen8, PUA/Firseria.aona
6.82%

G Data
Trojan.Generic.12212911, Gen:Variant.Application.Kazy.525798, Gen:Variant.Application.Bundler.44
6.82%

Vba32 AntiVirus
Downware.Morstar
6.82%

The domain dl.desk1992get.com has been seen to resolve to the following 9 IP addresses.

May 16, 2016

February 26, 2016

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
February 12, 2016

a96-6-113-32.deploy.akamaitechnologies.com
May 6, 2015

a96-6-113-24.deploy.akamaitechnologies.com
May 6, 2015

a184-51-126-88.deploy.static.akamaitechnologies.com
February 15, 2015

a184-51-126-105.deploy.static.akamaitechnologies.com
February 15, 2015

a23-62-7-137.deploy.static.akamaitechnologies.com
November 30, 2014

a23-62-7-161.deploy.static.akamaitechnologies.com
November 30, 2014

File downloads found at URLs served by dl.desk1992get.com.

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Virtual Personality.exe  (59dfe8f361a06750846592ad9590d81e)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Adobe Flash Player.exe  (78db87b04b86cba49ec86d53fde0f2fe)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Java Runtime.exe  (92fa6543708de7ea06b6233155577e9a)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../FLV_Media_Player.exe  (e6c038ba9a77ed6cbc36c6af18a470e0)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Tango.exe  (6145f0a3aa33ec0e47b6a96e1fd46194)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Retrica.exe  (963edbc6f7f8f67cf68eee398220942e)

1 / 68      (Adware)
http://dl.desk1992get.com/n/3.2.6/.../eMule060.exe  (2160114a5bfbe2672085e1aed6c2b158)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Ares Galaxy.exe  (b8ec7f230c8d67db0e641ae4ec5b9133)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../WeChat Installer.exe  (653eade44997f50fc332d7e71597b8bc)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../WeChat.exe  (6c7e178135448fecc2e89ca45a0144af)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Google Chrome.exe  (56b7a1495daed6406cb98d1827eef783)

1 / 68      (Adware)
http://dl.desk1992get.com/n/3.2.122/.../Adobe Reader.exe  (64b5a631e65a51cd841539486b2e8c77)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Google Chrome.exe  (d1575e5feaca688ca7c978db0c023e43)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../eroot_v1.3.4.exe.exe  (c4a3cbd37b3ad4e3a01baee290de89b1)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../AVG Anti-Virus Free.exe  (9317a5a80ff301c88af82659f6649e81)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../File_Downloader.exe  (56b10e024d11c49068c60851499b98a7)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Setup.exe  (2d2d0ffc1e514b18d2a6a8436a0f745c)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.desk1992get.com/n/3.2.75/.../MediaGet.exe  (01d841c25201344d2a2135e990d82c7e)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Skype.exe  (eaf06b8cf6c0ed4b7de7b3a196b12ecf)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Sonic Origins.exe  (bcea8d64bce9db3a52c28f44623256f5)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Avast! Free Antivirus.exe  (47494ddf7f5c3e19209678c431dcb076)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../aTube Catcher.exe  (4207c8ac36321d5a997ca05646660f04)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../Baidu Antivirus Free.exe  (5dc97edf020ffb3c8954d1930f3e5081)

1 / 68      (Adware)
http://dl.desk1992get.com/n/.../atube-catcher.exe  (23b2745bc0102c6df837a805e7c586d3)

 
Latest 30 of 45 download URLs

The following 609 files have been seen to comunicate with dl.desk1992get.com in live environments.

TCP » 54.72.9.51:80

 
Latest 20 of 627 files

URL:
http://dl.desk1992get.com/

Google Analytics:
UA-48689684

Title:
“Loading”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx/1.8.0

30 of 618 related domains