download.pdflite.com

Moniker Privacy Services  (Proxy Registrant)

Domain Information

The domain download.pdflite.com is registered by proxy through Moniker Online Services and was originally registered in February of 2011. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Remove Malware from download.pdflite.com - Powered by Reason Core Security
Registrar:
Moniker Online Services

Server location:
Virginia, United States (US)

Create date:
Thursday, February 24, 2011

Expires date:
Wednesday, February 24, 2016

Updated date:
Friday, February 13, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Clickrunsoftware.W, PUP.Installer.AmnisTechnology.Q, PUP.Installer.AmnisTechnology.S, PUP.Installer.AmnisTechnology.W
80.00%

Vba32 AntiVirus
BScope.Malware-Cryptor.MTA.01650, Adware.InstallCore.gen, suspected of Trojan.Downloader.gen.h
60.00%

Comodo Security
Application.Win32.ClickRun.A, UnclassifiedMalware
50.00%

Dr.Web
Adware.InstallCore.45, Trojan.MulDrop4.48137
50.00%

Avira AntiVirus
Adware/InstallC.Q.2, SPR/BitCoinMiner.AP, ADWARE/InstallCore.Gen
50.00%

ESET NOD32
Win32/InstallCore (variant), Win32/BitCoinMiner.BF (variant), Win32/InstallCore.BH (variant)
40.00%

Trend Micro House Call
TROJ_GE.5517C5C0, TROJ_GEN.RCEH1GC, TROJ_GEN.F47V0810, TROJ_GEN.RC1H1DR
40.00%

McAfee
Artemis!B58CBB39CB98, Artemis!C8534352E3F7, Artemis!18AFCD3284AD
30.00%

K7 AntiVirus
Unwanted-Program , Trojan
30.00%

avast!
Win32:InstallCore-FC [PUP], NSIS:BitCoinMiner-E [PUP], Win32:InstallCore-HF [PUP]
30.00%

McAfee Web Gateway
Artemis!B58CBB39CB98, Artemis!C8534352E3F7, Artemis!18AFCD3284AD
30.00%

Antiy Labs AVL
Trojan/Win32.SGeneric, WebToolbar/Win32.InstallCore.gen
30.00%

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594, PE:Trojan.Win32.Generic.147C5B7F!343694207, PE:AdWare.Win32.InstallCore.i!1075350952
30.00%

NANO AntiVirus
Trojan.Win32.WebToolbar.rgwpp, Riskware.Win32.InstallCore.nxxyd
30.00%

AhnLab V3 Security
PUP/Win32.InstallCore, Adware/Win32.InstallCore
30.00%

The domain download.pdflite.com has been seen to resolve to the following 63 IP addresses.

server-54-230-103-240.iad2.r.cloudfront.net
December 15, 2015

server-54-230-103-196.iad2.r.cloudfront.net
December 15, 2015

server-54-230-103-189.iad2.r.cloudfront.net
December 15, 2015

server-54-230-103-188.iad2.r.cloudfront.net
December 15, 2015

server-54-230-103-134.iad2.r.cloudfront.net
December 15, 2015

server-54-230-103-58.iad2.r.cloudfront.net
December 15, 2015

server-54-230-103-45.iad2.r.cloudfront.net
December 15, 2015

server-54-230-103-44.iad2.r.cloudfront.net
December 15, 2015

server-54-230-52-99.jfk6.r.cloudfront.net
May 5, 2015

server-54-192-55-23.jfk6.r.cloudfront.net
May 5, 2015

server-54-192-55-20.jfk6.r.cloudfront.net
May 5, 2015

server-54-192-55-201.jfk6.r.cloudfront.net
May 5, 2015

server-54-230-52-241.jfk6.r.cloudfront.net
May 5, 2015

server-54-230-52-164.jfk6.r.cloudfront.net
May 5, 2015

server-54-192-55-202.jfk6.r.cloudfront.net
May 5, 2015

server-54-192-54-186.jfk6.r.cloudfront.net
May 5, 2015

server-54-230-16-237.iad12.r.cloudfront.net
December 2, 2014

server-54-240-160-233.iad12.r.cloudfront.net
December 2, 2014

server-54-240-160-220.iad12.r.cloudfront.net
December 2, 2014

server-54-230-19-209.iad12.r.cloudfront.net
December 2, 2014

server-54-230-18-216.iad12.r.cloudfront.net
December 2, 2014

server-54-230-18-99.iad12.r.cloudfront.net
December 2, 2014

server-54-230-17-105.iad12.r.cloudfront.net
December 2, 2014

server-54-230-16-254.iad12.r.cloudfront.net
December 2, 2014

server-54-230-18-78.iad12.r.cloudfront.net
November 1, 2014

server-54-230-17-227.iad12.r.cloudfront.net
November 1, 2014

server-54-230-17-150.iad12.r.cloudfront.net
November 1, 2014

server-54-230-17-135.iad12.r.cloudfront.net
November 1, 2014

server-54-230-17-32.iad12.r.cloudfront.net
November 1, 2014

server-54-230-16-233.iad12.r.cloudfront.net
November 1, 2014

 
Showing 30 of 63 IP Addresses

File downloads found at URLs served by download.pdflite.com.

11 / 68    (PUP)
http://download.pdflite.com/setup-pdflite-ic-0.6.1.exe  (736cd48a61b19aea2d867ebf5e24465e)

2 / 68      (PUP)
http://download.pdflite.com/setup-pdfliteg.exe  (106c6b09893e047d00b50141b97a910c)

2 / 68      (PUP)
http://download.pdflite.com/setup-pdfliteo.exe  (b551cd456c1e5450bba065c480f0e3ce)

15 / 68    (PUP)

10 / 68    (PUP)
http://download.pdflite.com/setup-pdflite-ic-0.7.exe  (icreinstall_setup-pdflite-ic-0.7.exe)

21 / 68    (Adware)
http://download.pdflite.com/setup-pdflite-ic-0.7-aw.exe  (b58cbb39cb98698ba284e3593f9d8ea3)

35 / 68    (PUP)
http://download.pdflite.com/setup-pdflite-ic-0.6.1.exe  (01e83aab6fff22c0408c0ad410f25508)

1 / 68      (PUP)
http://download.pdflite.com/setup-pdflite-0.10.0.0-im.exe  (76bafb99a86fea4163cf8d76eb1270b4)

1 / 68      (PUP)
http://download.pdflite.com/setup-pdflite-0.9.0.0.exe  (0b9347ca635e9a826d954549622be8ce)

1 / 68      (PUP)
http://download.pdflite.com/setup-pdflite-0.7.exe  (eae5f6d1142859a08d10d31519a870af)

The following 36 files have been seen to comunicate with download.pdflite.com in live environments.

 
Latest 20 of 36 files

URL:
http://download.pdflite.com/

Network:
Amazon Cloudfront

Web server:
AmazonS3

Remove Malware from download.pdflite.com - Powered by Reason Core Security