www.richmediaplayer.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.richmediaplayer.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2011. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Wednesday, March 30, 2011

Expires date:
Monday, March 30, 2015

Updated date:
Thursday, July 11, 2013

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.RadiocomCJSC.P, PUP.Installer.RadiocomCJSC.R, PUP.Radiocom.Installer.Meta (M)
100.00%

AVG
Downloader, Potentially harmful program Downloader.ASQ
50.00%

Clam AntiVirus
Win.Trojan.Opencandy
25.00%

The domain www.richmediaplayer.com has been seen to resolve to the following IP address.

ec2-23-21-223-72.compute-1.amazonaws.com
February 7, 2014

File downloads found at URLs served by www.richmediaplayer.com.

1 / 68      (PUP)
http://www.richmediaplayer.com/.../richmediaplayer.exe  (3079352a559658f98b57085b834a81d5)

3 / 68      (Adware)

2 / 68      (Adware)
http://www.richmediaplayer.com/.../richmediaplayer.exe  (48a17dca1ed01c8541981701427182d9)

1 / 68      (Adware)
http://www.richmediaplayer.com/.../richmediaplayer.exe  (b42576f2a820d536c2d16f3bcf3f438d)

The following 26 files have been seen to comunicate with www.richmediaplayer.com in live environments.

 
Latest 20 of 26 files

URL:
http://www.richmediaplayer.com/

Google Analytics:
UA-35800153

Title:
“Rich Media Player - Watch any video you can imagine”

Network:
Amazon Web Services (AWS), running an EC2 instance

SSL certificate subject:
CN=richmediaplayer.com, OU=Domain Control Validated

SSL certificate issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, O="GoDaddy.com, Inc."

Web server:
Apache (PHP/5.3.23)

Facebook:
Likes:  745
Shares:  3,997
Comments:  87

Twitter:
Shares:  373

Compete.com:
US visitors:  11,977

Quantcast US:
Rank:  599,843

Statistics are for the previous month.