download.download-paint.net

CyberCast

Domain Information

The domain download.download-paint.net registered by CyberCast was initially registered in August of 2012 through 1 API GMBH. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
1 API GMBH

Server location:
Virginia, United States (US)

Create date:
Tuesday, August 28, 2012

Expires date:
Friday, August 28, 2015

Updated date:
Monday, July 28, 2014

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (75% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.MaxSetup.T, PUP.installCore (M)
100.00%

Malwarebytes
PUP.Optional.InstallCore
66.67%

Agnitum Outpost
PUA.InstallCore
66.67%

VIPRE Antivirus
InstallCore.b
66.67%

Avira AntiVirus
ADWARE/InstallCore.Gen7
66.67%

Sophos
Install Core Click run software
66.67%

G Data
Win32.Application.InstallCore
66.67%

ESET NOD32
Win32/InstallCore.MJ (variant)
66.67%

AVG
MalSign.InstallC
66.67%

The domain download.download-paint.net has been seen to resolve to the following 2 IP addresses.

ec2-23-23-240-198.compute-1.amazonaws.com
September 9, 2014

ec2-54-225-220-83.compute-1.amazonaws.com
April 14, 2014

File downloads found at URLs served by download.download-paint.net.

9 / 68      (Adware)

URL:
http://download.download-paint.net/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx (PHP/5.5.9-1ubuntu4.3)