www.torntv-downloader-dl.info

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.torntv-downloader-dl.info is registered by proxy through GoDaddy.com, LLC (R171-LRMS). This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GoDaddy.com, LLC (R171-LRMS)

Server location:
Arizona, United States (US)

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.TanjaMatkovic.R, PUP.CoolMirage.P, PUP.HARASANPRAPAPON.?, PUP.HARASANPRAPAPON.c, PUP.KantidaChanudrum.f, PUP.KantidaChanudrum.u, PUP.TanjaMatkovic.Installer (M), PUP.CoolMirage (M)
96.77%

Malwarebytes
PUP.Optional.OneClickDownloader.A
83.87%

Qihoo 360 Security
Win32/Virus.Adware.47b, HEUR/Malware.QVM06.Gen
77.42%

G Data
NSIS.Adware.OneClickDownloader, NSIS.Application.OneClickDownloader, Application.Bundler.BK
74.19%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
64.52%

Trend Micro House Call
TROJ_GEN.F47V0228, TROJ_GEN.F47V0602, Suspicious_GEN.F47V0630, Suspicious_GEN.F47V0701, Suspicious_GEN.F47V0702, Suspicious_GEN.F47V0710
45.16%

VIPRE Antivirus
CoolMirage Ltd, BubbleDock, Trojan.Win32.Generic
45.16%

Dr.Web
Adware.Yontoo.4, Adware.Downware.1263, Adware.Downware.5516, Trojan.DownLoad3.33864, Adware.Yontoo.11, Adware.Downware.6586
41.94%

AVG
Generic, Rungnapa, Berta
35.48%

NANO AntiVirus
Riskware.Nsis.Downware.czyjkl, Trojan.Nsis.Yotoon.deckrr
29.03%

Avira AntiVirus
APPL/CoolMirage.AD.134, APPL/CoolMirage.Gen
29.03%

McAfee
Artemis!4FE00C5838CD, Artemis!02A8E61B1281, Artemis!1CA8A22D3296, Artemis!8B3AC90D8EE9, Artemis!2C169A82DAAD, Artemis!370806B8CC9D, Artemis!000F7A8B7F7F, Artemis!E357D85DE7C2
25.81%

Sophos
1 Click Downloader, CoolMirage, FT Downloader
22.58%

McAfee Web Gateway
Artemis!4FE00C5838CD, Artemis!02A8E61B1281, Artemis!1CA8A22D3296, Artemis!8B3AC90D8EE9, Artemis!2C169A82DAAD
22.58%

ESET NOD32
Win32/AdWare.1ClickDownload.AR, Win32/AdWare.1ClickDownload.AT
12.90%

The domain www.torntv-downloader-dl.info has been seen to resolve to the following 10 IP addresses.

ip-184-168-221-42.ip.secureserver.net
June 30, 2015

ec2-184-169-157-32.us-west-1.compute.amazonaws.com
November 29, 2014

ec2-50-18-168-176.us-west-1.compute.amazonaws.com
November 18, 2014

ec2-50-18-172-232.us-west-1.compute.amazonaws.com
September 30, 2014

ec2-54-241-253-59.us-west-1.compute.amazonaws.com
September 7, 2014

ec2-50-18-104-209.us-west-1.compute.amazonaws.com
August 10, 2014

ec2-184-169-158-115.us-west-1.compute.amazonaws.com
August 7, 2014

ec2-184-169-175-49.us-west-1.compute.amazonaws.com
May 5, 2014

ec2-54-215-5-252.us-west-1.compute.amazonaws.com
February 27, 2014

ec2-204-236-130-106.us-west-1.compute.amazonaws.com
February 27, 2014

File downloads found at URLs served by www.torntv-downloader-dl.info.

10 / 68    (Adware)

7 / 68      (Adware)

12 / 68    (Adware)

10 / 68    (Adware)
http://www.torntv-downloader-dl.info/.../Sunny.Leone.Goddess.DVDRip.XxX.exe  (elvis_presley_1977_06_26_the_last_farewell_1_dvd_plg.exe)

10 / 68    (Adware)
http://www.torntv-downloader-dl.info/.../Zombeavers_(2014)_HdRip.exe  (mp3_-_192kbps_oasis_-_stop_the_clocks.exe)

9 / 68      (Adware)

6 / 68      (Adware)

13 / 68    (Adware)

10 / 68    (Adware)
http://www.torntv-downloader-dl.info/.../09_01_2014_celebrity_nude_photo_hack_collection_fappening.exe  (il_signore_degli_anelli___la_battaglia_per_la_terra_di_mezzo_ii__tntvillage_org_.exe)

7 / 68      (Adware)

7 / 68      (Adware)
http://www.torntv-downloader-dl.info/.../The_Legend_of_Hercules_(2014).exe  (hannibal_s01_season_1_720p_bluray_x264-demand.exe)

10 / 68    (Adware)
http://www.torntv-downloader-dl.info/.../arcgis_10_1_crack.exe  (grip_op_de_groep_van_engelen_verified.exe)

10 / 68    (PUP)

9 / 68      (Adware)

6 / 68      (Adware)

7 / 68      (Adware)

10 / 68    (PUP)

9 / 68      (Adware)

6 / 68      (Adware)

 
Latest 30 of 59 download URLs

The following 9 files have been seen to comunicate with www.torntv-downloader-dl.info in live environments.

URL:
http://www.torntv-downloader-dl.info/

Title:
“TornTV”

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)