flv1.dmrcdn.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain flv1.dmrcdn.com is registered by proxy through GODADDY.COM, LLC and was originally registered in July of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Friday, July 5, 2013

Expires date:
Sunday, July 5, 2015

Updated date:
Sunday, July 6, 2014

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Stepitapp.K, PUP.Installer.AppsInstallerSL.L, PUP.Solimba.AppsInst.Bundler (M)
100.00%

Kaspersky
not-a-virus:Downloader.Win32.Agent, not-a-virus:Downloader.Win32.Morstar
66.67%

VIPRE Antivirus
Conduit, Trojan.Win32.Generic
66.67%

Vba32 AntiVirus
Downloader.Agent, Downware.Morstar
66.67%

Panda Antivirus
Trj/Chgt.C, Trj/Genetic.gen
66.67%

McAfee
Artemis!304697BCACC1
33.33%

Trend Micro House Call
Suspicious_GEN.F47V0804
33.33%

Malwarebytes
PUP.Optional.InstallerSL
33.33%

NANO AntiVirus
Trojan.Win32.MulDrop5.dcygsx
33.33%

avast!
Win32:Adware-BQN [Trj]
33.33%

Sophos
Solimba Installer
33.33%

Comodo Security
Application.Win32.Firseria.MAP
33.33%

Dr.Web
Trojan.MulDrop5.34677
33.33%

Avira AntiVirus
APPL/Firseria.Gen
33.33%

G Data
Win32.Application.Morstar
33.33%

The domain flv1.dmrcdn.com has been seen to resolve to the following 4 IP addresses.

lb-182-248.above.com
June 19, 2016

unallocated.barefruit.co.uk
May 3, 2015

ec2-75-101-142-114.compute-1.amazonaws.com
December 11, 2014

ec2-54-235-219-29.compute-1.amazonaws.com
December 11, 2014

File downloads found at URLs served by flv1.dmrcdn.com.

1 / 68      (Adware)
http://flv1.dmrcdn.com/n/3.1.20/.../videoplayer.exe  (aac622af7a48e9553b8a8e76400a19db)

29 / 68    (Adware)
http://flv1.dmrcdn.com/n/3.1.20/.../videoplayer.exe  (d6a73d0d6e6aad785bf28b9aeaedb470)

29 / 68    (Adware)
http://flv1.dmrcdn.com/n/.../videoplayer.exe  (d6a73d0d6e6aad785bf28b9aeaedb470)

7 / 68      (Adware)
http://flv1.dmrcdn.com/n/3.1.20/.../Setup.exe  (304697bcacc1f75fbdb90394f7b7469a)

7 / 68      (Adware)
http://flv1.dmrcdn.com/n/.../Setup.exe  (304697bcacc1f75fbdb90394f7b7469a)

The following 235 files have been seen to comunicate with flv1.dmrcdn.com in live environments.

 
Latest 20 of 235 files

URL:
http://flv1.dmrcdn.com/

Web server:
nginx/1.0.15

Twitter:
Shares:  62

Statistics are for the previous month.