dl.downloadwizard.com

Download Manager  (via a Proxy Registrant)

Domain Information

The domain dl.downloadwizard.com is registered by proxy through ENOM, INC. and was originally registered in April of 2000. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Digital Ocean, Inc. network. The domain is associated with the publisher Download Manager who is located in Victoria, British Columbia in Canada.
Registrar:
ENOM, INC.

Server location:
New York, United States (US)

Create date:
Wednesday, April 12, 2000

Expires date:
Wednesday, April 12, 2017

Updated date:
Monday, March 14, 2016

ASN:
AS393406 DIGITALOCEAN-ASN-NY3 - Digital Ocean, Inc.,US

Root domain:

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Air Software.DownloadAssistant.Bundler (M), PUP.Air Software.Download.Bundler (M), PUP.Vittalia.InstallH.Installer (M), Threat.Win.Reputation.IMP, PUP.Air Software (M), PUP.Vittalia (M)
100.00%

VIPRE Antivirus
Threat.4782985
4.26%

ESET NOD32
Win32/DownloadAssistant.A potentially unwanted application
4.26%

Dr.Web
Trojan.Vittalia.34, Trojan.Vittalia.30
4.26%

avast!
Win32:Adware-CKE [PUP], Win32:Adware-CKC [PUP]
4.26%

Bkav FE
W32.HfsAdware
4.26%

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.32
2.13%

F-Secure
Riskware.Gen:Variant.Application.Bundler
2.13%

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.32
2.13%

MicroWorld eScan
Gen:Variant.Application.Bundler.32
2.13%

Malwarebytes
PUP.Optional.DownloadAssistant
2.13%

Bitdefender
Gen:Variant.Application.Bundler.32
2.13%

G Data
Win32.Application.DownloadAssistant
2.13%

AVG
Generic
2.13%

Qihoo 360 Security
Malware.QVM10.Gen
2.13%

The domain dl.downloadwizard.com has been seen to resolve to the following 3 IP addresses.

fd-04-do-w-sf-1.gtdlrfwd.com
July 16, 2016

fd-03-do-e-ny-3.gtdlrfwd.com
October 29, 2015

useast.gtdlrfwd.com
September 30, 2014

File downloads found at URLs served by dl.downloadwizard.com.

The following 46 files have been seen to comunicate with dl.downloadwizard.com in live environments.

 
Latest 20 of 47 files

URL:
http://dl.downloadwizard.com/

Title:
“Welcome to nginx!”

Web server:
nginx/1.4.6 (Ubuntu)