download.mediaplay.ru

Private Person  (Proxy Registrant)

Domain Information

The domain download.mediaplay.ru is registered by proxy through RU-CENTER-RU and was originally registered in January of 2009. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Remove Malware from download.mediaplay.ru - Powered by Reason Core Security
Registrar:
RU-CENTER-RU

Server location:
Moscow City, Russia (RU)

Create date:
Thursday, January 22, 2009

Expires date:
Friday, January 22, 2016

ASN:
AS48347 MTW-AS JSC MediaSoft Ekspert

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Dr.Web
Adware.Downware.1659, Adware.Downware.2208, Program.MediaGet.21
100.00%

Trend Micro House Call
TROJ_GEN.F47V0306, TROJ_GEN.F47V0430, TROJ_GEN.F47V0220, TROJ_GEN.F47V0325, Suspicious_GEN.F47V0815, Suspicious_GEN.F47V1213
77.78%

McAfee
Artemis!B002EC343B01, Artemis!64254B0B3CA4, Artemis!81DC82DB35E2, Artemis!13852D9EFF52, Artemis!58EFC35138E3, Artemis!F1149968D2F6
66.67%

McAfee Web Gateway
Artemis!B002EC343B01, Artemis!64254B0B3CA4, Artemis!81DC82DB35E2, Artemis!13852D9EFF52, Artemis!58EFC35138E3
66.67%

ESET NOD32
Win32/Amonetize (variant), Win32/Amonetize.AJ (variant), Win32/MediaGet.AF (variant), Win32/MediaGet.AF potentially unwanted (variant)
66.67%

AhnLab V3 Security
PUP/Win32.Amonetize
55.56%

AVG
Media
55.56%

avast!
Win32:Amonetize-I [PUP], Win32:Amonetize-Q [PUP], Win32:Amonetize-N [PUP]
44.44%

Sophos
Amonetize, Generic PUA HJ
44.44%

K7 Gateway Antivirus
Unwanted-Program , Trojan
33.33%

K7 AntiVirus
Unwanted-Program , Trojan
33.33%

Reason Heuristics
Threat.Win.Reputation.IMP
33.33%

Fortinet FortiGate
Riskware/Amonetize
22.22%

Avira AntiVirus
ADWARE/Adware.Gen2, PUA/MediaGet.Gen
22.22%

Vba32 AntiVirus
AdWare.Amonetize, Downloader.MediaGet
22.22%

The domain download.mediaplay.ru has been seen to resolve to the following IP address.

discounttoday.ru
March 14, 2014

File downloads found at URLs served by download.mediaplay.ru.

5 / 68      (PUP)

8 / 68      (PUP)
http://download.mediaplay.ru/download.php?r=softportal  (record_megamix_by_magnit_slider_-_radio_record_16_id2137854ids1s.exe)

8 / 68      (PUP)
http://download.mediaplay.ru/download2.php?r=unionpeer.org  (record_megamix_by_magnit_slider_-_radio_record_16_id2137854ids1s.exe)

11 / 68    (PUP)
http://download.mediaplay.ru/download.php?comment=o479  (tomorrowland_2013_official_song_first_day_of_tomo_id1170210ids1s.exe)

8 / 68      (PUP)

3 / 68      (PUP)

10 / 68    (PUP)

6 / 68      (PUP)

5 / 68      (PUP)

11 / 68    (PUP)

9 / 68      (PUP)

URL:
http://download.mediaplay.ru/

Web server:
nginx/1.4.3

Remove Malware from download.mediaplay.ru - Powered by Reason Core Security