www.mediaplayerlite.net

Moniker Privacy Services  (Proxy Registrant)

Domain Information

The domain www.mediaplayerlite.net is registered by proxy through Moniker Online Services and was originally registered in September of 2011. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
Moniker Online Services

Server location:
Virginia, United States (US)

Create date:
Saturday, September 24, 2011

Expires date:
Saturday, September 24, 2016

Updated date:
Sunday, September 13, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ISfreemium.U, PUP.WorldSetup.U, PUP.Installer.BestDownloadManager.P, PUP.Installer.InstallX.AA, PUP.MaxSetup.U, PUP.Installer.Statscom.V, PUP.Installer.DownloadAdmin.V, PUP.Installer.CodeTechno.V, PUP.STMSetup.U, (M), PUP.Tightrope.DownloadAdmin.Bundler (M), PUP.installCore.MaxSetup (M), PUP.installCore.STMSetup (M), PUP.InstallX.Installer (M), PUP.Tightrope.Zoobam.Bundler (M), PUP.Adknowledge.SailMach.Bundler (M), PUP.Tightrope.Download.Bundler (M), PUP.installCore.ISfreemi (M), PUP.Adknowledge.Seekinst.Bundler (M), PUP.Tightrope (M)
91.18%

Dr.Web
Trojan.Packed.25266, Adware.Plugin.85, Trojan.Packed.24524, Adware.W3i.32, Adware.DAdmin.151, Adware.InstallCore.386, Adware.Downware.2220
47.06%

VIPRE Antivirus
InstallCore, sterkly LLC, InstallIQ Installer, Threat.4788237, Threat.4783369, DownloadAdmin, Threat.4786018
47.06%

AVG
AdInject.Bdmngr, InstallCore, Generic, InstallIQ.F
35.29%

Agnitum Outpost
Riskware.Agent, PUA.InstallCore, PUA.Downware
32.35%

Avira AntiVirus
ADWARE/InstallCore.Gen7, APPL/InstallIQ.Gen5, ADWARE/InstallCore.Gen9, APPL/Downloader.Gen, ADWARE/Adware.Gen, PUA/InstallCore.Gen7
29.41%

Malwarebytes
PUP.Optional.Freemium.A, PUP.Optional.BundleInstaller.A, PUP.Optional.InstallIQ, PUP.Optional.DownloadAdmin, PUP.PlayPickle
26.47%

ESET NOD32
Win32/InstallCore.DO (variant), Win32/KBM (variant), Win32/InstallCore.CH (variant), Win32/InstallIQ (variant), Win32/DownloadAdmin
26.47%

McAfee
Artemis!8D4C47D900B9, Artemis!339651B4EDF0, Artemis!69C9B09B9E20, CryptInno, Artemis!2A7B349E86B2, Trojan.Artemis!B168BA37827B
26.47%

Trend Micro House Call
TROJ_GEN.F47V1217, TROJ_GEN.F47V0920, Suspici.B577CD42, Suspicious_GEN.F47V0708, TROJ_GEN.F47V0815
26.47%

herdProtect (fuzzy)
a variant of 894e872b5dd00d1524d4b6741e781f62a4c0bbea, a variant of e596438def6d56847c7d59c71eb149400d673f95, a variant of b45d582494005d694750177c3eb6b00a6857914e
20.59%

Sophos
Install Core Click run software, InstallQ
20.59%

ESET NOD32
Win32/InstallCore.MJ potentially unwanted application, Win32/DownloadAdmin.G potentially unwanted application, Win32/InstallCore.PL potentially unwanted application, Win32/DownloadAdmin.H potentially unwanted application
20.59%

Fortinet FortiGate
Riskware/MultiPlug, Riskware/FirseriaInstaller, Riskware/DownloadAdmin, Riskware/InstallIQ
17.65%

F-Secure
Adware:W32/WebInstallBundle
17.65%

The domain www.mediaplayerlite.net has been seen to resolve to the following 159 IP addresses.

server-52-84-125-37.iad16.r.cloudfront.net
September 14, 2016

server-52-84-125-220.iad16.r.cloudfront.net
September 14, 2016

server-52-84-125-179.iad16.r.cloudfront.net
September 14, 2016

server-52-84-125-167.iad16.r.cloudfront.net
September 14, 2016

server-52-84-125-137.iad16.r.cloudfront.net
September 14, 2016

server-52-84-125-111.iad16.r.cloudfront.net
September 14, 2016

server-52-84-125-43.iad16.r.cloudfront.net
September 14, 2016

server-54-192-19-112.iad12.r.cloudfront.net
August 25, 2016

server-54-192-19-9.iad12.r.cloudfront.net
August 25, 2016

server-54-192-19-211.iad12.r.cloudfront.net
August 25, 2016

server-54-192-19-173.iad12.r.cloudfront.net
August 25, 2016

server-54-192-19-130.iad12.r.cloudfront.net
August 25, 2016

server-54-192-19-125.iad12.r.cloudfront.net
August 25, 2016

server-54-192-19-23.iad12.r.cloudfront.net
August 22, 2016

server-54-192-19-18.iad12.r.cloudfront.net
August 22, 2016

server-54-192-19-207.iad12.r.cloudfront.net
August 22, 2016

server-54-192-19-186.iad12.r.cloudfront.net
August 22, 2016

server-54-192-19-144.iad12.r.cloudfront.net
August 22, 2016

server-54-192-19-127.iad12.r.cloudfront.net
August 22, 2016

server-54-192-19-77.iad12.r.cloudfront.net
August 22, 2016

server-54-192-19-58.iad12.r.cloudfront.net
August 22, 2016

server-52-85-131-76.iad53.r.cloudfront.net
July 20, 2016

server-52-85-131-56.iad53.r.cloudfront.net
July 20, 2016

server-52-85-131-22.iad53.r.cloudfront.net
July 20, 2016

server-52-85-131-18.iad53.r.cloudfront.net
July 20, 2016

server-52-85-131-202.iad53.r.cloudfront.net
July 20, 2016

server-52-85-131-195.iad53.r.cloudfront.net
July 20, 2016

server-52-85-131-178.iad53.r.cloudfront.net
July 20, 2016

server-52-85-131-120.iad53.r.cloudfront.net
July 20, 2016

server-52-85-131-172.iad53.r.cloudfront.net
May 27, 2016

 
Showing 30 of 159 IP Addresses

File downloads found at URLs served by www.mediaplayerlite.net.

1 / 68      (Adware)
http://www.mediaplayerlite.net/download  (mediaplayerlite-setup.exe)

1 / 68      (Adware)

1 / 68      (Malware)
http://www.mediaplayerlite.net/download2  (setup-mediaplayerlite-0.5.3.2.exe)

The following 229 files have been seen to comunicate with www.mediaplayerlite.net in live environments.

 
Latest 20 of 478 files

URL:
http://www.mediaplayerlite.net/

Google Analytics:
UA-21970171

Title:
“Free Audio and Video Player Software - Free Audio and Video Player Software - Media Player LiteFree Audio and Video Player Software – Media Player Lite | MediaPlayerLite is a free open source ...”

Description:
“MediaPlayerLite is a free open source audio and video player on Windows. You can play DVD, AVI, mpeg, FLV, MP4, WMV, MOV, DivX, XviD & more! Play your video and audio now completely free! Features - what can MediaPlayerLite do? Video, Image &...”

Network:
Amazon Cloudfront

Web server:
AmazonS3

Facebook:
Likes:  2
Shares:  66
Comments:  3

Statistics are for the previous month.