mirror10.msgpluslive.net

Yuna Software

Domain Information

The domain mirror10.msgpluslive.net registered by Yuna Software was initially registered in November of 2005 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
GODADDY.COM, LLC

Server location:
New York, United States (US)

Create date:
Wednesday, November 9, 2005

Expires date:
Thursday, January 5, 2017

Updated date:
Thursday, December 25, 2014

Root domain:

Scanner detections:
Detections  (93% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/MessengerPlus (variant), Win32/InstallCore (variant), Win32/MessengerPlus.A potentially unwanted (variant)
95.35%

Reason Heuristics
PUP.Optional.Installer.YunaSoftwareLimited.L, PUP.Optional.Installer.YunaSoftwareLimited.R, PUP.Optional.Installer.V, PUP.Optional.Installer.P, Win32.Generic.Installer.Meta, Win32.Generic.YunaSoftware.Installer.Meta
95.35%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
53.49%

McAfee
Artemis!20E1DC25DC4C, Artemis!6F84BD93A461, Artemis!DA9B0CB7FC2B, Artemis!8C9A37BC02E3, Artemis!A18D2E80051A, Artemis!09D9D5A2EF88, RDN/Generic PUP.x!clm, Artemis!351312D5A25C, Artemis!B8EEE0909EC7
25.58%

Trend Micro House Call
TROJ_GEN.F47V1203, TROJ_GEN.F47V0218, BKDR_BIFROSE.BMC, TROJ_GEN.F47V1122, TROJ_GEN.F47V0114, TROJ_GEN.F47V0526, TROJ_GEN.R02SH06HP14, Suspicious_GEN.F47V0121
23.26%

Baidu Antivirus
Trojan.Win32.MessengerPlus, PUA.Win32.MessengerPlus
16.28%

Dr.Web
Trojan.Lyrics.284, Trojan.Lyrics.844, Trojan.Inject1.28681
13.95%

AVG
MalSign.Resoft, Worm/Delf.KHX
11.63%

Emsisoft Anti-Malware
Trojan.Generic.9204806, Trojan.Agent.AROC, Worm.Generic.377772
11.63%

IKARUS anti.virus
AdWare.MessengerPlus, PUA.MessengerPlus
11.63%

Bkav FE
W32.Clodc5b.Trojan, W32.Clod985.Trojan, W32.HfsAdware
9.30%

avast!
Win32:Dropper-gen [Drp], Win32:Agent-AODJ [Trj]
6.98%

ESET NOD32
Win32/MessengerPlus.A potentially unwanted application, Win32/Delf.NRJ worm
6.98%

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
4.65%

K7 AntiVirus
Trojan
4.65%

The domain mirror10.msgpluslive.net has been seen to resolve to the following 270 IP addresses.

server-52-84-125-187.iad16.r.cloudfront.net
August 24, 2016

server-52-84-125-110.iad16.r.cloudfront.net
August 24, 2016

server-52-84-125-80.iad16.r.cloudfront.net
August 24, 2016

server-52-84-125-51.iad16.r.cloudfront.net
August 24, 2016

server-52-84-125-15.iad16.r.cloudfront.net
August 24, 2016

server-52-84-125-218.iad16.r.cloudfront.net
August 24, 2016

server-52-85-131-24.iad53.r.cloudfront.net
July 18, 2016

server-52-85-131-181.iad53.r.cloudfront.net
July 18, 2016

server-52-85-131-162.iad53.r.cloudfront.net
July 18, 2016

server-52-85-131-86.iad53.r.cloudfront.net
July 18, 2016

server-52-85-131-44.iad53.r.cloudfront.net
July 18, 2016

server-52-85-131-39.iad53.r.cloudfront.net
July 18, 2016

server-52-85-131-201.iad53.r.cloudfront.net
July 5, 2016

server-52-85-131-121.iad53.r.cloudfront.net
July 5, 2016

server-52-85-131-67.iad53.r.cloudfront.net
July 5, 2016

server-52-85-131-243.iad53.r.cloudfront.net
July 5, 2016

server-52-85-131-229.iad53.r.cloudfront.net
July 5, 2016

server-52-85-131-225.iad53.r.cloudfront.net
July 5, 2016

server-52-85-131-219.iad53.r.cloudfront.net
July 5, 2016

server-52-84-125-120.iad16.r.cloudfront.net
July 5, 2016

server-52-84-125-32.iad16.r.cloudfront.net
July 5, 2016

server-52-84-125-19.iad16.r.cloudfront.net
July 5, 2016

server-52-84-125-198.iad16.r.cloudfront.net
July 5, 2016

server-52-84-125-188.iad16.r.cloudfront.net
July 5, 2016

server-52-84-125-150.iad16.r.cloudfront.net
July 5, 2016

server-52-84-125-142.iad16.r.cloudfront.net
July 5, 2016

server-52-85-131-228.iad53.r.cloudfront.net
June 20, 2016

server-52-85-131-214.iad53.r.cloudfront.net
June 20, 2016

server-52-85-131-198.iad53.r.cloudfront.net
June 20, 2016

server-52-85-131-172.iad53.r.cloudfront.net
June 20, 2016

 
Showing 30 of 270 IP Addresses

File downloads found at URLs served by mirror10.msgpluslive.net.

9 / 68      (PUP)

2 / 68      (PUP)

1 / 68      (PUP)

2 / 68      (PUP)

10 / 68    (Malware)

3 / 68      (PUP)

9 / 68      (PUP)

2 / 68      (PUP)

6 / 68      (PUP)

2 / 68      (PUP)

3 / 68      (PUP)

5 / 68      (PUP)

2 / 68      (PUP)

5 / 68      (PUP)

2 / 68      (PUP)

4 / 68      (PUP)

0 / 68

2 / 68      (PUP)

0 / 68
http://mirror10.msgpluslive.net/MsgPlus-363.exe  (69141ed02e182eec409a2899d56421ed)

7 / 68      (PUP)

10 / 68    (PUP)

5 / 68      (PUP)

11 / 68    (PUP)

2 / 68      (PUP)

5 / 68      (PUP)

7 / 68      (PUP)

5 / 68      (PUP)

 
Latest 30 of 68 download URLs

The following 165 files have been seen to comunicate with mirror10.msgpluslive.net in live environments.

 
Latest 20 of 325 files

URL:
http://mirror10.msgpluslive.net/

Network:
Amazon Cloudfront

Web server:
AmazonS3

Facebook:
Shares:  1

Statistics are for the previous month.