hd-plugin.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain hd-plugin.com is registered by proxy through GODADDY.COM, LLC and was originally registered in February of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Remove Malware from hd-plugin.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Thursday, February 07, 2013

Expires date:
Tuesday, February 07, 2017

Updated date:
Monday, February 08, 2016

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

VIPRE Antivirus
CoolMirage Ltd, Trojan.Win32.Generic, Threat.4783938, Threat.4721115
84.62%

Reason Heuristics
PUP.Installer.VASSANAKONGSOONGNERN.Q, PUP.VASSANAKONGSOONGNERN.K, PUP.CHUTCHAIKIEWNOY.Q, PUP.VASSANAKONGSOONGNERN.Q, PUP.VASSANAKONGSOONGNERN.S
84.62%

Kaspersky
not-a-virus:AdWare.NSIS.Yontoo, not-a-virus:Downloader.Win32.TornTV, Packed.Win32.Krap
76.92%

Dr.Web
Adware.Downware.8319, Threat.Undefined, Adware.Yontoo.54, Win32.Sector.30
76.92%

AVG
Generic, Win32/Sality
76.92%

Sophos
CoolMirage, Generic PUA LE, PUA 'CoolMirage', Virus 'Mal/Sality-D'
53.85%

K7 AntiVirus
Adware , Trojan-Downloader , Riskware
53.85%

K7 Gateway Antivirus
Adware , Trojan-Downloader , Riskware
46.15%

Baidu Antivirus
Adware.NSIS.Yontoo, Trojan.Win32.Krap
38.46%

McAfee
Artemis!853654972DB5, Artemis!1009B0450E65, Artemis!0B50402C066A, Trojan.Artemis!3306632A8818
30.77%

McAfee Web Gateway
BehavesLike.Win32.BadFile.lc, BehavesLike.Win32.CryptDoma.lc, BehavesLike.Win32.BadFile.kc, Artemis
30.77%

ESET NOD32
NSIS/TrojanDownloader.Adload, NSIS/TrojanDownloader.Adload.AC
30.77%

avast!
Win32:Rootkit-gen [Rtk], Win32:Sality
23.08%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/NSIS.Yontoo.n
23.08%

G Data
Win32.Trojan.Agent.R8I40Q, Win32.Application.Agent.3LIORS
15.38%

The domain hd-plugin.com has been seen to resolve to the following 11 IP addresses.

ip-50-63-202-41.ip.secureserver.net
February 12, 2016

ec2-54-246-121-152.eu-west-1.compute.amazonaws.com
November 19, 2015

ec2-54-246-120-161.eu-west-1.compute.amazonaws.com
July 16, 2015

ec2-176-34-107-151.eu-west-1.compute.amazonaws.com
June 18, 2015

ec2-54-217-233-226.eu-west-1.compute.amazonaws.com
May 3, 2015

ec2-54-228-201-246.eu-west-1.compute.amazonaws.com
May 3, 2015

ec2-184-169-157-32.us-west-1.compute.amazonaws.com
November 2, 2014

ec2-50-18-168-176.us-west-1.compute.amazonaws.com
October 24, 2014

ec2-54-241-253-59.us-west-1.compute.amazonaws.com
September 2, 2014

ec2-50-18-104-209.us-west-1.compute.amazonaws.com
August 16, 2014

ec2-184-169-175-49.us-west-1.compute.amazonaws.com
May 14, 2014

File downloads found at URLs served by hd-plugin.com.

13 / 68    (PUP)

15 / 68    (Adware)

6 / 68      (Adware)

8 / 68      (Adware)

10 / 68    (Adware)

15 / 68    (Adware)

8 / 68      (Adware)

10 / 68    (Adware)

 
Latest 30 of 63 download URLs

The following 8 files have been seen to comunicate with hd-plugin.com in live environments.

May 14, 2014

July 6, 2014

URL:
http://hd-plugin.com/

Web server:
Microsoft-IIS/7.5

Remove Malware from hd-plugin.com - Powered by Reason Core Security