dlforall.net

United Privacy Corp

Domain Information

The domain dlforall.net registered by United Privacy Corp was initially registered in September of 2015 through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Beaumaris, Victoria within Australia which resides on the Asia Pacific Network Information Centre network.
Registrar:
NAMEPAL.COM #8013

Server location:
Victoria, Australia (AU)

Create date:
Friday, September 11, 2015

Expires date:
Sunday, September 11, 2016

Updated date:
Wednesday, February 24, 2016

ASN:
AS133618 TRELLIAN-AS-AP Trellian Pty. Limited,AU

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.InstallMonetizer, PUP.Optional.Amonetize, PUP.Optional.Amonetize.A, PUP.Optional.Downloader, PUP.Optional.OptimumInstaller.A
83.33%

Reason Heuristics
PUP.Installer.Amonetizeltd.EE, PUP.Installer.Amonetizeltd.h, PUP.Installer.Amonetizeltd.S, PUP.Installer.ShetefSolutionsConsulting1998.n, PUP.Installer.SystemApplet.N, PUP.MediaStroy.Installer (M), PUP.MediaStr.Installer (M), Adware.Amonetize.Installer.Meta (M), PUP.Adknowledge.FusionIn.Bundler (M), Win32.Generic, PUP.Adknowledge (M), Adware.Amonetize (M)
83.33%

avast!
Win32:Dropper-gen [Drp], Win32:Amonetize-E [PUP], Win32:Adware-BJY [PUP], Win32:Amonetize-N [PUP], Win32:Amonetize-AM [PUP], Win32:Amonetize-BJ [PUP]
73.81%

ESET NOD32
Win32/Amonetize (variant), Win32/Amonetize.AD (variant), Win32/Amonetize.AG (variant), Win32/Amonetize.AI (variant), Win32/Amonetize.AJ (variant)
71.43%

Sophos
Amonetize, Generic PUA IA, iBryte Optimum Installer
66.67%

Avira AntiVirus
ADWARE/Adware.Gen2, APPL/Amonetize.Z, ADWARE/Adware.Gen7
64.29%

McAfee
Artemis!4476FBE0C98B, Adware-Amonetize!01060DF48554, Adware-Amonetize!BE0E2E71EA9E, Artemis!97EC61C98BD1, Adware-Amonetize!0DE7113F0DBA, Artemis!1F1DC4062D17, Artemis!AC04B4FDAB43, RDN/Generic PUP.x!b2u, Artemis!74705E1F9812, PUP-FBM!EC904BB78BBD, PUP-FBM!7219B3E0F438, PUP-FBM!CD6B5CE6DA50, PUP-FBM!3C9FB2588A89, Artemis!373DB4089762, Artemis!A88731362644
61.90%

AhnLab V3 Security
PUP/Win32.Amonetiz, PUP/Win32.Amonetize, PUP/Win32.OptimumInstaller
59.52%

AVG
MalSign.Generic, Generic_r, MalSign.Wilmo, Generic5, BundleApp_r.R, Adware BundleApp_r.R, Adware AdPlugin, Adware Generic_s
59.52%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize, not-a-virus:AdWare.Win32.Amonetize, not-a-virus:AdWare.Win32.iBryte
59.52%

McAfee Web Gateway
Artemis!4476FBE0C98B, Adware-Amonetize!01060DF48554, Adware-Amonetize!BE0E2E71EA9E, Artemis!97EC61C98BD1, Adware-Amonetize!0DE7113F0DBA
57.14%

Dr.Web
Adware.Downware.1655, Adware.Downware.1833, Adware.Downware.2467, Adware.Downware.3033, Adware.Downware.3925, Adware.Downware.5451, Trojan.Amonetize.353
50.00%

VIPRE Antivirus
Amonetize, Trojan.Win32.Generic, Threat.4778314
50.00%

NANO AntiVirus
Riskware.Win32.Downware.cyusqp, Riskware.Win32.Downware.daymkg, Riskware.Win32.Amonetize.czmmii, Riskware.Win32.Downware.dbcwox
50.00%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus,HEUR]/Win32.Amonetize, GrayWare[AdWare:not-a-virus]/Win32.Amonetize, Riskware[:not-a-virus]/Win32.iBryte.jgi
45.24%

The domain dlforall.net has been seen to resolve to the following 5 IP addresses.

July 19, 2016

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
June 28, 2016

lb-182-241.above.com
April 17, 2016

October 7, 2015

February 5, 2014

File downloads found at URLs served by dlforall.net.

1 / 68      (PUP)

42 / 68    (PUP)

20 / 68    (Adware)

12 / 68    (Adware)

6 / 68      (PUP)

6 / 68      (PUP)

26 / 68    (Adware)
http://dlforall.net/.../?id=p191&sub=ar&name={filename}&nor=1&subid=9978677122  (mk4.service.and.repair.manual.mondeo__7818_i1108078479_il2.exe)

32 / 68    (PUP)

32 / 68    (PUP)

 
Latest 30 of 123 download URLs

The following 228 files have been seen to comunicate with dlforall.net in live environments.

TCP » 54.72.9.51:80

 
Latest 20 of 234 files

URL:
http://dlforall.net/

Title:
“dlforall.net”

Web server:
Apache

Facebook:
Shares:  1

Statistics above are for the previous month of May 2017.