dl.getprivate.net

Techsnab LLC

Domain Information

The domain dl.getprivate.net registered by Techsnab LLC was initially registered in May of 2013 through INTERNETWORX LTD. & CO. KG. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Remove Malware from dl.getprivate.net - Powered by Reason Core Security
Registrar:
INTERNETWORX LTD. & CO. KG

Server location:
Arizona, United States (US)

Create date:
Monday, May 27, 2013

Expires date:
Friday, May 27, 2016

Updated date:
Thursday, May 28, 2015

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Root domain:

Scanner detections:
Detections  (79% detected)

Scan engine
Details
Detections

Dr.Web
Adware.Privitize.2
94.12%

VIPRE Antivirus
GetPrivate, Threat.4790103, Threat.4150696
94.12%

Malwarebytes
PUP.Optional.BundleInstaller.A, PUP.Optional.GetPrivate.A
76.47%

ESET NOD32
Win32/Toolbar.Montiera.I potentially unwanted application, Win32/Toolbar.Babylon.F potentially unwanted application, Win32/Techsnab.A potentially unwanted application
52.94%

F-Prot
W32/OpenCandy.A, W32/A-6c385e4c, W32/OpenCandy.A (exact, not disinfectable)
50.00%

Zillya! Antivirus
Trojan.Agent.Win32.434110, Adware.Techsnab.Win32.3
44.12%

Qihoo 360 Security
Malware.QVM06.Gen, HEUR/QVM42.0.Malware.Gen
35.29%

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5, NSIS:PUF.HiddenInstaller!1.9C64, PE:Trojan.Agentb!6.232C, PE:Trojan.Agentb!6.232C[F1], PE:PUF.OpenCandy!1.9DE5[F1]
32.35%

K7 AntiVirus
Adware , Unwanted-Program
26.47%

Trend Micro House Call
TROJ_GEN.F47V0225, Suspicious_GEN.F47V0701, Suspicious_GEN.F47V0713
26.47%

Vba32 AntiVirus
AdWare.JS.Taggy, AdWare.DelBar, TrojanDropper.Agent, suspected of Crafted.Win32File.OLS
23.53%

IKARUS anti.virus
not-a-virus:WebToolbar.Win32.Rubar, AdWare.MySearchDial, PUA.VisualTools
20.59%

Reason Heuristics
PUP.Installer.Techsnab.P, PUP.Techsnab.s, PUP.Techsnab., PUP.Techsnab.h, PUP.Techsnab.Installer (M)
20.59%

ESET NOD32
Win32/OpenCandy, Win32/Techsnab (variant)
17.65%

NANO AntiVirus
Trojan.Win32.Babylon.csuksh, Trojan.Win32.Toolbar.dgukom, Riskware.Nsis.Privitize.dqgttj, Riskware.Nsis.Adware.dtddyg, Trojan.Win32.OpenCandy.dwzazk
17.65%

The domain dl.getprivate.net has been seen to resolve to the following 4 IP addresses.

July 23, 2014

July 23, 2014

December 25, 2013

December 25, 2013

File downloads found at URLs served by dl.getprivate.net.

1 / 68      (PUP)

5 / 68      (PUP)

5 / 68      (PUP)

3 / 68      (PUP)

14 / 68    (PUP)

9 / 68      (PUP)

5 / 68      (PUP)

11 / 68    (PUP)

12 / 68    (PUP)

7 / 68      (PUP)

0 / 68
http://dl.getprivate.net/index.php/.../ESET_NOD32_Antivirus_6.0.316_(English)_Activation_ _Keys_-L3G3ND.exe  (eset_nod32_antivirus_6.0.316_(english)_activation_ _keys_-l3g3nd.exe)

0 / 68

URL:
http://dl.getprivate.net/

SSL certificate subject:
CN=sni23557.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx

Remove Malware from dl.getprivate.net - Powered by Reason Core Security