dl.searchdealsapp.com

CloudCanvas, Inc.  (via a Proxy Registrant)

Domain Information

The domain dl.searchdealsapp.com is registered by proxy through GODADDY.COM, LLC and was originally registered in June of 2011. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below). The domain is associated with the publisher CloudCanvas, Inc. who is located in Wilmington, Delaware in the United States.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Thursday, June 16, 2011

Expires date:
Thursday, January 01, 2015

Updated date:
Wednesday, November 20, 2013

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.CloudCanvas.F, PUP.CloudCan.Installer (M)
100.00%

MicroWorld eScan
Adware.Agent.NVF
50.00%

nProtect
Adware.Agent.NVF
50.00%

McAfee
Artemis!6FEAAAAC38EB
50.00%

Malwarebytes
PUP.Optional.SearchDonkey.A
50.00%

NANO AntiVirus
Trojan.Win32.Plugin.ctuood
50.00%

avast!
Win32:BHO-AMO [PUP]
50.00%

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
50.00%

Bitdefender
Adware.Agent.NVF
50.00%

Lavasoft Ad-Aware
Adware.Agent.NVF
50.00%

Emsisoft Anti-Malware
Adware.Agent.NVF
50.00%

F-Secure
Adware.Agent.NVF
50.00%

Dr.Web
Adware.Plugin.128
50.00%

VIPRE Antivirus
Trojan.Win32.Generic
50.00%

McAfee Web Gateway
Artemis!6FEAAAAC38EB
50.00%

The domain dl.searchdealsapp.com has been seen to resolve to the following 16 IP addresses.

server-52-84-125-214.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-203.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-186.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-119.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-80.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-52.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-39.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-37.iad16.r.cloudfront.net
July 17, 2016

server-54-230-37-161.jfk1.r.cloudfront.net
April 14, 2014

server-54-230-39-200.jfk1.r.cloudfront.net
April 14, 2014

server-54-230-37-59.jfk1.r.cloudfront.net
April 14, 2014

server-54-230-36-240.jfk1.r.cloudfront.net
April 14, 2014

server-54-230-36-234.jfk1.r.cloudfront.net
April 14, 2014

server-54-230-36-198.jfk1.r.cloudfront.net
April 14, 2014

server-204-246-169-64.jfk1.r.cloudfront.net
April 14, 2014

server-54-230-38-34.jfk1.r.cloudfront.net
April 14, 2014

File downloads found at URLs served by dl.searchdealsapp.com.

1 / 68      (Adware)

20 / 68    (Adware)

The following 26 files have been seen to comunicate with dl.searchdealsapp.com in live environments.

 
Latest 20 of 49 files

URL:
http://dl.searchdealsapp.com/

Network:
Amazon Cloudfront

Web server:
AmazonS3