media.downloadster.org

Downloadster  (via a Proxy Registrant)

Domain Information

downloadster distributes apps with its download manager which bundles adware toolbars such as Babylon and Rally as well as other potentially unwanted software. "We're able to offer free software because we are advertiser supported. When you download software, it gives our advertisers a chance to speak to you. ALL OFFERS ARE OPTIONAL. Users may be offered to change their browser homepage during install." The domain media.downloadster.org is registered by proxy through GoDaddy.com, LLC (R91-LROR). This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below). The domain is associated with the publisher Downloadster who is located in SAN FRANCISCO, California in the United States.
Remove Malware from media.downloadster.org - Powered by Reason Core Security
Registrar:
GoDaddy.com, LLC (R91-LROR)

Server location:
New York, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.SecureInstaller.J, PUP.Installer.Clickrunsoftware.J
100.00%

Sophos
Install Core, Install Core Click run software
100.00%

VIPRE Antivirus
InstallCore, Click run software
100.00%

Avira AntiVirus
ADWARE/InstallCore.Gen, APPL/Downloader.Gen6
100.00%

Vba32 AntiVirus
BScope.Malware-Cryptor.InstallCore.2691
100.00%

Bkav FE
W32.HfsAutoA
50.00%

K7 AntiVirus
Unwanted-Program
50.00%

K7 Gateway Antivirus
Unwanted-Program
50.00%

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
50.00%

F-Prot
W32/InstallCore.G.gen
50.00%

Comodo Security
Application.Win32.ClickRun.A
50.00%

Dr.Web
Adware.InstallCore.68
50.00%

ESET NOD32
Win32/InstallCore.AF (variant)
50.00%

The domain media.downloadster.org has been seen to resolve to the following 13 IP addresses.

August 13, 2014

August 13, 2014

(CloudFlare)
August 13, 2014

August 13, 2014

August 13, 2014

server-54-230-55-39.jfk6.r.cloudfront.net
December 27, 2013

server-54-230-54-113.jfk6.r.cloudfront.net
December 27, 2013

server-54-240-190-33.jfk6.r.cloudfront.net
December 27, 2013

server-54-230-53-251.jfk6.r.cloudfront.net
December 27, 2013

server-54-230-55-79.jfk6.r.cloudfront.net
December 27, 2013

server-54-230-55-84.jfk6.r.cloudfront.net
December 27, 2013

server-54-240-190-153.jfk6.r.cloudfront.net
December 27, 2013

server-54-240-190-136.jfk6.r.cloudfront.net
December 27, 2013

File downloads found at URLs served by media.downloadster.org.

9 / 68      (Adware)
http://media.downloadster.org/setup_vlc.exe  (8d9f424cd4747876f07110bc336a49fb)

9 / 68      (PUP)
http://media.downloadster.org/setup_vlc.exe  (bb383d1c1b3e3d4899de443d9c903a60)

The following file have been seen to comunicate with media.downloadster.org in live environments.

URL:
http://media.downloadster.org/

Network:
Amazon Cloudfront

SSL certificate subject:
CN=ssl2575.cloudflare.com, O="CloudFlare, Inc.", L=San Francisco, S=CA, C=US

SSL certificate issuer:
CN=GlobalSign Organization Validation CA - G2, O=GlobalSign nv-sa, C=BE

Web server:
cloudflare-nginx

Remove Malware from media.downloadster.org - Powered by Reason Core Security