The domain mirror10.msgpluslive.net registered by Yuna Software was initially registered in November of 2005 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
GODADDY.COM, LLC
Server location:
New York, United States (US)
Create date:
Wednesday, November 9, 2005
Expires date:
Thursday, January 5, 2017
Updated date:
Thursday, December 25, 2014
Scanner detections:
Detections (93% detected)
Scan engine
Details
Detections
ESET NOD32
Win32/MessengerPlus (variant), Win32/InstallCore (variant), Win32/MessengerPlus.A potentially unwanted (variant)
95.35%
Reason Heuristics
PUP.Optional.Installer.YunaSoftwareLimited.L, PUP.Optional.Installer.YunaSoftwareLimited.R, PUP.Optional.Installer.V, PUP.Optional.Installer.P, Win32.Generic.Installer.Meta, Win32.Generic.YunaSoftware.Installer.Meta
95.35%
Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
53.49%
McAfee
Artemis!20E1DC25DC4C, Artemis!6F84BD93A461, Artemis!DA9B0CB7FC2B, Artemis!8C9A37BC02E3, Artemis!A18D2E80051A, Artemis!09D9D5A2EF88, RDN/Generic PUP.x!clm, Artemis!351312D5A25C, Artemis!B8EEE0909EC7
25.58%
Trend Micro House Call
TROJ_GEN.F47V1203, TROJ_GEN.F47V0218, BKDR_BIFROSE.BMC, TROJ_GEN.F47V1122, TROJ_GEN.F47V0114, TROJ_GEN.F47V0526, TROJ_GEN.R02SH06HP14, Suspicious_GEN.F47V0121
23.26%
Baidu Antivirus
Trojan.Win32.MessengerPlus, PUA.Win32.MessengerPlus
16.28%
Dr.Web
Trojan.Lyrics.284, Trojan.Lyrics.844, Trojan.Inject1.28681
13.95%
AVG
MalSign.Resoft, Worm/Delf.KHX
11.63%
Emsisoft Anti-Malware
Trojan.Generic.9204806, Trojan.Agent.AROC, Worm.Generic.377772
11.63%
IKARUS anti.virus
AdWare.MessengerPlus, PUA.MessengerPlus
11.63%
Bkav FE
W32.Clodc5b.Trojan, W32.Clod985.Trojan, W32.HfsAdware
9.30%
avast!
Win32:Dropper-gen [Drp], Win32:Agent-AODJ [Trj]
6.98%
ESET NOD32
Win32/MessengerPlus.A potentially unwanted application, Win32/Delf.NRJ worm
6.98%
Qihoo 360 Security
HEUR/Malware.QVM06.Gen
4.65%
The domain mirror10.msgpluslive.net has been seen to resolve to the following 270 IP addresses.
server-52-84-125-187.iad16.r.cloudfront.net
August 24, 2016
server-52-84-125-110.iad16.r.cloudfront.net
August 24, 2016
server-52-84-125-80.iad16.r.cloudfront.net
August 24, 2016
server-52-84-125-51.iad16.r.cloudfront.net
August 24, 2016
server-52-84-125-15.iad16.r.cloudfront.net
August 24, 2016
server-52-84-125-218.iad16.r.cloudfront.net
August 24, 2016
server-52-85-131-24.iad53.r.cloudfront.net
July 18, 2016
server-52-85-131-181.iad53.r.cloudfront.net
July 18, 2016
server-52-85-131-162.iad53.r.cloudfront.net
July 18, 2016
server-52-85-131-86.iad53.r.cloudfront.net
July 18, 2016
server-52-85-131-44.iad53.r.cloudfront.net
July 18, 2016
server-52-85-131-39.iad53.r.cloudfront.net
July 18, 2016
server-52-85-131-201.iad53.r.cloudfront.net
July 5, 2016
server-52-85-131-121.iad53.r.cloudfront.net
July 5, 2016
server-52-85-131-67.iad53.r.cloudfront.net
July 5, 2016
server-52-85-131-243.iad53.r.cloudfront.net
July 5, 2016
server-52-85-131-229.iad53.r.cloudfront.net
July 5, 2016
server-52-85-131-225.iad53.r.cloudfront.net
July 5, 2016
server-52-85-131-219.iad53.r.cloudfront.net
July 5, 2016
server-52-84-125-120.iad16.r.cloudfront.net
July 5, 2016
server-52-84-125-32.iad16.r.cloudfront.net
July 5, 2016
server-52-84-125-19.iad16.r.cloudfront.net
July 5, 2016
server-52-84-125-198.iad16.r.cloudfront.net
July 5, 2016
server-52-84-125-188.iad16.r.cloudfront.net
July 5, 2016
server-52-84-125-150.iad16.r.cloudfront.net
July 5, 2016
server-52-84-125-142.iad16.r.cloudfront.net
July 5, 2016
server-52-85-131-228.iad53.r.cloudfront.net
June 20, 2016
server-52-85-131-214.iad53.r.cloudfront.net
June 20, 2016
server-52-85-131-198.iad53.r.cloudfront.net
June 20, 2016
server-52-85-131-172.iad53.r.cloudfront.net
June 20, 2016
Showing 30 of 270 IP Addresses
File downloads found at URLs served by mirror10.msgpluslive.net.
Latest 30 of 68 download URLs
The following 165 files have been seen to comunicate with mirror10.msgpluslive.net in live environments.
URL:
http://mirror10.msgpluslive.net/
Network:
Amazon Cloudfront
Statistics are for the previous month.