The domain download.aminst.net registered by Jan Everno was initially registered in October of 2014 through INTERNET.BS CORP.. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the OVH Hosting, Inc. network. The domain is associated with the publisher Amonetize ltd. who is located in Raanana, Alberta in Israel.
Registrar:
BETTERTHANAVERAGEDOMAINS.COM LLC
Server location:
Quebec, Canada (CA)
Create date:
Wednesday, October 15, 2014
Expires date:
Saturday, October 15, 2016
Updated date:
Friday, October 30, 2015
Scanner detections:
Detections (96% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.ShetefSolutionsConsulting1998.?, PUP.Installer.Amonetizeltd.i, PUP.Installer.Amonetizeltd.V, PUP.Installer.ShetefSolutionsConsulting1998., PUP.Installer.ShetefSolutionsConsulting1998.j, PUP.Installer.ShetefSolutionsConsulting1998.x, PUP.Installer.Amonetizeltd.T, PUP.Installer.ShetefSolutionsConsulting1998.p, PUP.Installer.Amonetizeltd.?, PUP.Installer.ShetefSolutionsConsulting1998.l, PUP.Amonetize (M)
96.00%
Malwarebytes
PUP.Optional.InstallMonetizer, PUP.Optional.Amonetize.A, PUP.Optional.Amonetize.AS, PUP.Optional.Monetizer
92.00%
ESET NOD32
Win32/Amonetize (variant), Win32/Amonetize.AA (variant), Win32/Amonetize.S potentially unwanted (variant)
92.00%
Avira AntiVirus
ADWARE/Adware.Gen2, Adware/Amonetize.Q.2
84.00%
Dr.Web
Adware.Downware.1575, Adware.Downware.1528
80.00%
Trend Micro House Call
TROJ_GEN.F47V1205, TROJ_GEN.F47V1214, TROJ_GEN.F47V1222, TROJ_GEN.F47V1125, TROJ_GEN.F47V1017, TROJ_GEN.F47V1217, TROJ_GEN.F47V1011
64.00%
IKARUS anti.virus
not-a-virus:Downloader.Win32.Agent, Win32.Malware, AdWare.Amonetize
60.00%
VIPRE Antivirus
Amonetize, Conduit
60.00%
McAfee
Artemis!53597284E965, Artemis!17945562CC68, Artemis!311F3AB701D4, Artemis!D770A95564A8, Artemis!CD1FFC3696D4, Artemis!A892424AD6E1, Artemis!9026520E9EF5, Artemis!2A82B348D96C, Artemis!F12182204DF9
56.00%
Fortinet FortiGate
Riskware/Amonetize, W32/Amonetize.W, Adware/Fam.NB, Riskware/Agent
48.00%
avast!
Win32:Dropper-gen [Drp], Win32:Amonetize-E [PUP], Win32:Rootkit-gen [Rtk], Win32:Malware-gen, Win32:Amonetize-Q [PUP], Win32:PUP-gen [PUP]
40.00%
Comodo Security
ApplicUnwnt
40.00%
AhnLab V3 Security
PUP/Win32.Amonetiz
32.00%
G Data
Win32.Trojan.Agent.V3ANE4, Win32.Trojan.Agent.OXERD6, Win32.Trojan.Agent.3F5QSY, Adware.Generic.605883, Win32.Application.Amonetize
28.00%
Panda Antivirus
Trj/dtcontx.I, Trj/OCJ.D, Suspicious file
20.00%
The domain download.aminst.net has been seen to resolve to the following 16 IP addresses.
ns513839.ip-167-114-156.net
May 3, 2015
ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
March 6, 2014
26-143-116-62.rev.customer-net.de
February 2, 2014
25-143-116-62.rev.customer-net.de
January 28, 2014
(CloudFlare)
January 17, 2014
(CloudFlare)
January 17, 2014
(CloudFlare)
December 18, 2013
(CloudFlare)
December 18, 2013
File downloads found at URLs served by download.aminst.net.
Latest 30 of 403 download URLs
The following 249 files have been seen to comunicate with download.aminst.net in live environments.
URL:
http://download.aminst.net/
Title:
“aminst.net - This website is for sale! - aminst Resources and Information.”
Title (12/18/2013):
“aminst.net”
Title (11/29/2014):
“aminst.net - This website is for sale! - aminst Resources and Information.”
Web server:
Apache (PHP/5.3.3-7+squeeze28)
Related Domains