secure.rocketdlgo.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain secure.rocketdlgo.com is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in San Jose, California within the United States which resides on the CDNetworks Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
California, United States (US)

Create date:
Tuesday, October 08, 2013

Expires date:
Wednesday, October 08, 2014

Updated date:
Tuesday, October 08, 2013

Root domain:

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF, PE:Trojan.Win32.Generic.13FF7F71!335511409
63.41%

Dr.Web
Adware.Searcher.2593, Adware.Downware.918, Adware.Downware.1243, Trojan.DownLoad3.25843, Trojan.BPlug.13, Trojan.MulDrop4.22250
60.98%

Malwarebytes
PUP.Optional.InstallMonetizer.A, PUP.Optional.Squirrelweb.A, PUP.Optional.Jotzey.A
48.78%

Reason Heuristics
PUP.Installer.squirrelweb.Q, PUP.Installer.BrowserDistributionServices.V, (M), PUP.Installer.DuuquGroupOU.Q, PUP.Installer.WeatherWarnings.H, PUP.Installer.Applon.Y, PUP.BigBulbIdeasITPvt.Y, PUP.StartInstall.BB
39.02%

Trend Micro House Call
TROJ_GEN.F47V1213, TROJ_GEN.F47V1215, TROJ_GEN.F47V0104, TROJ_GEN.F47V1224, TROJ_GEN.F47V0111, TROJ_GEN.F47V0124, TROJ_GEN.F47V0227
36.59%

VIPRE Antivirus
InstallMonetizer, Wajam, Threat.4786532
29.27%

NANO AntiVirus
Trojan.Win32.Searcher.cjaztx, Riskware.Win32.Searcher.csnymk, Trojan.Win32.MulDrop4.cfecrq, Riskware.Nsis.Toolbar.cvzrwd
26.83%

avast!
NSIS:InstMonetizer-AR [PUP], NSIS:Downloader-ZK [PUP], NSIS:InstMonetizer-AW [PUP], NSIS:InstMonetizer-AX [PUP], NSIS:InstMonetizer-BB [PUP]
26.83%

SUPERAntiSpyware
Heur.Agent/Gen-WhiteBox
24.39%

Antiy Labs AVL
Trojan[Packed]/Win32.Katusha, Trojan/Win32.SGeneric
24.39%

Kaspersky
not-a-virus:Downloader.Win32.Agent, not-a-virus:Downloader.NSIS.Agent, not-a-virus:AdWare.NSIS.InstallMonetizer
21.95%

ESET NOD32
Win32/InstallMonetizer.AZ potentially unwanted application, Win32/InstallMonetizer.AG potentially unwanted application, Win32/InstallMonetizer.BC potentially unwanted application
21.95%

ESET NOD32
Win32/InstallMonetizer.AG, Win32/InstallMonetizer.AZ
19.51%

AVG
MultiBundle.D, Generic, Adware BundleApp.MSC, Generic_c, Adware Generic_c.WT
19.51%

Avira AntiVirus
TR/Mitglieder.1440907, APPL/Downloader.Gen
17.07%

The domain secure.rocketdlgo.com has been seen to resolve to the following 10 IP addresses.

September 27, 2014

September 27, 2014

September 22, 2014

September 22, 2014

May 30, 2014

May 30, 2014

May 1, 2014

May 1, 2014

March 15, 2014

March 15, 2014

File downloads found at URLs served by secure.rocketdlgo.com.

1 / 68      (Adware)

8 / 68      (PUP)

4 / 68      (PUP)
http://secure.rocketdlgo.com/nsi/.../nteworks_5171.exe  (6d23c60620999f6a377fa079e266ebcf)

4 / 68      (PUP)

3 / 68      (PUP)

4 / 68      (PUP)
http://secure.rocketdlgo.com/nsi/.../CaptainSafe_8218.exe  (f9dd8ee8935170f2efd606da1b969097)

7 / 68      (PUP)

18 / 68    (PUP)

1 / 68      (Malware)
http://secure.rocketdlgo.com/nsi/.../pmadeploy_5605.exe  (64bee2483ec234035a1e62811408d3d2)

5 / 68      (PUP)

2 / 68      (Adware)

5 / 68      (Adware)

4 / 68      (PUP)

14 / 68    (PUP)

1 / 68      (Malware)

24 / 68    (PUP)

3 / 68      (Adware)
http://secure.rocketdlgo.com/.../SquirrelWebSetup.exe  (1138c95f6a00fb56143557a8a549c7dc)

2 / 68      (Adware)
http://secure.rocketdlgo.com/.../BringStarSetup.exe  (cdf20531762260bf341e2f22df85cbcf)

2 / 68      (Adware)
http://secure.rocketdlgo.com/.../DuuquUpdateSetup.exe  (55f0045d54c3425e96335ebeffa29181)

2 / 68      (Adware)

10 / 68    (PUP)

10 / 68    (Adware)

4 / 68      (inconclusive)

7 / 68      (Adware)

6 / 68      (PUP)
http://secure.rocketdlgo.com/nsi/.../gear01_1931.exe  (70e177a2907dd703596b95b90dd39481)

4 / 68      (Adware)

The following 21 files have been seen to comunicate with secure.rocketdlgo.com in live environments.

 
Latest 20 of 78 files

URL:
http://secure.rocketdlgo.com/

Web server:
PWS/8.0.25

Alexa:
Global rank:  8,804,719
Backlinks:  5

Compete.com:
US visitors:  9,335

Statistics are for the previous month (Alexa statistics are for entire rocketdlgo.com).