media.downloadster.org

Downloadster

Domain Information

downloadster distributes apps with its download manager which bundles adware toolbars such as Babylon and Rally as well as other potentially unwanted software. "We're able to offer free software because we are advertiser supported. When you download software, it gives our advertisers a chance to speak to you. ALL OFFERS ARE OPTIONAL. Users may be offered to change their browser homepage during install." This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below). The domain is associated with the publisher Downloadster who is located in SAN FRANCISCO, California in the United States.
Registrar:
Ulysses S. Grant, LLC

Server location:
New York, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.SecureInstaller.J, PUP.Installer.Clickrunsoftware.K, PUP.Installer.Clickrunsoftware.J, PUP.Clickrunsoftware.R
100.00%

Sophos
Install Core, Install Core Click run software
100.00%

VIPRE Antivirus
InstallCore, Click run software
100.00%

Avira AntiVirus
ADWARE/InstallCore.Gen, APPL/Downloader.Gen6
100.00%

Vba32 AntiVirus
BScope.Malware-Cryptor.InstallCore.2691, BScope.Malware-Cryptor.MTA.01650
75.00%

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
75.00%

Comodo Security
Application.Win32.ClickRun.A
75.00%

Dr.Web
Adware.InstallCore.45, Adware.InstallCore.68, Adware.MediaFinder.2
75.00%

ESET NOD32
Win32/InstallCore (variant), Win32/InstallCore.AF (variant)
75.00%

K7 AntiVirus
Unwanted-Program
50.00%

K7 Gateway Antivirus
Unwanted-Program
50.00%

McAfee
Artemis!5003C14F2FE6, Artemis!07629B4F3B8A
50.00%

Trend Micro House Call
TROJ_SPNR.0BFD13, TROJ_SPNR.0BHR12
50.00%

Trend Micro
TROJ_SPNR.0BFD13, TROJ_SPNR.0BHR12
50.00%

McAfee Web Gateway
Artemis!5003C14F2FE6, Artemis!07629B4F3B8A
50.00%

The domain media.downloadster.org has been seen to resolve to the following 14 IP addresses.

lb-182-244.above.com
April 7, 2016

August 13, 2014

August 13, 2014

(CloudFlare)
August 13, 2014

August 13, 2014

August 13, 2014

server-54-230-55-39.jfk6.r.cloudfront.net
December 27, 2013

server-54-230-54-113.jfk6.r.cloudfront.net
December 27, 2013

server-54-240-190-33.jfk6.r.cloudfront.net
December 27, 2013

server-54-230-53-251.jfk6.r.cloudfront.net
December 27, 2013

server-54-230-55-79.jfk6.r.cloudfront.net
December 27, 2013

server-54-230-55-84.jfk6.r.cloudfront.net
December 27, 2013

server-54-240-190-153.jfk6.r.cloudfront.net
December 27, 2013

server-54-240-190-136.jfk6.r.cloudfront.net
December 27, 2013

File downloads found at URLs served by media.downloadster.org.

21 / 68    (Adware)
http://media.downloadster.org/vlcplayer_install.exe  (07629b4f3b8a2ac0c9316ad342c8c08e)

15 / 68    (Adware)
http://media.downloadster.org/vlc_osetup.exe  (5003c14f2fe6688882956fcf6b49dc6b)

9 / 68      (Adware)
http://media.downloadster.org/setup_vlc.exe  (8d9f424cd4747876f07110bc336a49fb)

9 / 68      (PUP)
http://media.downloadster.org/setup_vlc.exe  (bb383d1c1b3e3d4899de443d9c903a60)

The following 2 files have been seen to comunicate with media.downloadster.org in live environments.

URL:
http://media.downloadster.org/

Network:
Amazon Cloudfront

Web server:
Apache (PHP/5.4.45-0+deb7u2)