hd-plugin.com

PERFECT PRIVACY, LLC  (Proxy Registrant)

Domain Information

The domain hd-plugin.com is registered by proxy through EASTEND DOMAINS, LLC and was originally registered in April of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
EASTEND DOMAINS, LLC

Server location:
Arizona, United States (US)

Create date:
Tuesday, April 26, 2016

Expires date:
Wednesday, April 26, 2017

Updated date:
Tuesday, April 26, 2016

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US

Scanner detections:
Detections  (90% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.VASSANAKONGSOONGNERN.Q, PUP.VASSANAKONGSOONGNERN.K, PUP.CHUTCHAIKIEWNOY.Q, PUP.VASSANAKONGSOONGNERN.Q, PUP.KanchanaKhiandee.Q, PUP.CoolMirage.VASSANAKONGSOONGNERN.Installer (M), PUP.ThitimaPhiwsawang.Installer (M)
100.00%

VIPRE Antivirus
CoolMirage Ltd, Trojan.Win32.Generic
57.89%

AVG
Generic
57.89%

Kaspersky
not-a-virus:AdWare.NSIS.Yontoo, not-a-virus:Downloader.Win32.TornTV
52.63%

Dr.Web
Adware.Downware.8319, Adware.Yontoo.54
52.63%

Sophos
CoolMirage, Kanchana Khiandee adware, Generic PUA LE, Generic PUA GK
47.37%

K7 Gateway Antivirus
Adware , Trojan-Downloader , Riskware
42.11%

K7 AntiVirus
Adware , Trojan-Downloader , Riskware
42.11%

McAfee Web Gateway
BehavesLike.Win32.BadFile.lc, BehavesLike.Win32.CryptDoma.lc, BehavesLike.Win32.BadFile.kc, BehavesLike.Win32.StartPage.kc
36.84%

McAfee
Artemis!853654972DB5, Artemis!F77A44832E45, Artemis!1009B0450E65, Artemis!71BF39324628, Artemis!0B50402C066A, Artemis!DA787EF9DE27
31.58%

Baidu Antivirus
Adware.NSIS.Yontoo, Hacktool.Win32.TornTV
26.32%

ESET NOD32
NSIS/TrojanDownloader.Adload, NSIS/TrojanDownloader.Adload.AC
26.32%

Avira AntiVirus
Adware/Yontoo.71608, Adware/Yontoo.71616, Adware/Yontoo.80336, Adware/Yontoo.77224
21.05%

Trend Micro House Call
Suspicious_GEN.F47V1113, Suspici.8B120837, TROJ_GEN.R02SC0EKD14, Suspicious_GEN.F47V0130
21.05%

avast!
Win32:Rootkit-gen [Rtk], Win32:Adware-gen [Adw]
15.79%

The domain hd-plugin.com has been seen to resolve to the following 15 IP addresses.

July 18, 2016

July 10, 2016

June 18, 2016

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
May 5, 2016

ip-50-63-202-41.ip.secureserver.net
February 12, 2016

ec2-54-246-121-152.eu-west-1.compute.amazonaws.com
November 19, 2015

ec2-54-246-120-161.eu-west-1.compute.amazonaws.com
July 16, 2015

ec2-176-34-107-151.eu-west-1.compute.amazonaws.com
June 18, 2015

ec2-54-217-233-226.eu-west-1.compute.amazonaws.com
May 3, 2015

ec2-54-228-201-246.eu-west-1.compute.amazonaws.com
May 3, 2015

ec2-184-169-157-32.us-west-1.compute.amazonaws.com
November 2, 2014

ec2-50-18-168-176.us-west-1.compute.amazonaws.com
October 24, 2014

ec2-54-241-253-59.us-west-1.compute.amazonaws.com
September 2, 2014

ec2-50-18-104-209.us-west-1.compute.amazonaws.com
August 16, 2014

ec2-184-169-175-49.us-west-1.compute.amazonaws.com
May 14, 2014

File downloads found at URLs served by hd-plugin.com.

8 / 68      (Adware)

8 / 68      (Adware)

14 / 68    (Adware)

 
Latest 30 of 138 download URLs

The following 231 files have been seen to comunicate with hd-plugin.com in live environments.

TCP » 54.72.9.51:80

 
Latest 20 of 237 files

May 14, 2014

July 6, 2014

URL:
http://hd-plugin.com/

Google Analytics:
UA-48689684

Title:
“hd-plugin.com”

Web server:
nginx

30 of 618 related domains