download.easydriverpro.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download.easydriverpro.net is registered by proxy through GODADDY.COM, LLC and was originally registered in February of 2011. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Saturday, February 12, 2011

Expires date:
Sunday, February 12, 2017

Updated date:
Tuesday, February 9, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (76% detected)

Scan engine
Details
Detections

Kaspersky
not-a-virus:Downloader.NSIS.Agent
85.42%

Dr.Web
Trojan.Siggen6.33552
81.25%

McAfee
Trojan.Artemis!A89FF500F30F, Trojan.Artemis!14236C067EE0, Trojan.Artemis!C63CC70393BD, Trojan.Artemis!EEF974037E86, RDN/Generic Downloader.x!nf, Program.Artemis!44391F8806E8, Trojan.Artemis!5152FFC1CC9B, Artemis!0A223BD7C0F4, Artemis!3939080C03E2, RDN/Generic Downloader.x!ny, Artemis!95E1ECEA2C46, RDN/Downloader.a!vu
56.25%

Vba32 AntiVirus
Downloader.Agent, suspected of Trojan.Downloader.gen.h
52.08%

Baidu Antivirus
Hacktool.NSIS.Agent
52.08%

Fortinet FortiGate
Riskware/Agent
50.00%

Panda Antivirus
Generic Suspicious, Trj/CI.A
50.00%

Zillya! Antivirus
Downloader.Agent.Win32.241947, Downloader.Agent.Win32.258487
47.92%

Trend Micro
TROJ_GEN.R047C0ECA15, TROJ_GEN.R03EC0PLM15, TROJ_GEN.R03EC0PI215
45.83%

Norman
Downloader, Trojan.Generic.14793659, Trojan.Generic.14538158, Trojan.Generic.14516026, Trojan.Generic.14828824, Trojan.Generic.14070732
43.75%

NANO AntiVirus
Trojan.Nsis.Agent.drxdjy, Riskware.Nsis.Downloader.drbdxi
37.50%

Trend Micro House Call
TROJ_GEN.R047C0ECA15, TROJ_GEN.R0C1H07BK15
35.42%

Emsisoft Anti-Malware
Trojan.Generic.13118251, Trojan.Generic.14538158, Trojan.Generic.14516026, Trojan.Generic.14499984, Trojan.Generic.14087788, Trojan.Generic.14070732, Trojan.Generic.13114371, Trojan.Generic.14782397
33.33%

Qihoo 360 Security
Win32/Virus.Downloader.dc3, QVM42.0.Malware.Gen, HEUR/QVM42.1.Malware.Gen
33.33%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696
18.75%

The domain download.easydriverpro.net has been seen to resolve to the following 249 IP addresses.

server-54-192-19-68.iad12.r.cloudfront.net
August 29, 2016

server-54-192-19-14.iad12.r.cloudfront.net
August 29, 2016

server-54-192-19-11.iad12.r.cloudfront.net
August 29, 2016

server-54-192-19-243.iad12.r.cloudfront.net
August 29, 2016

server-54-192-19-240.iad12.r.cloudfront.net
August 29, 2016

server-54-192-19-232.iad12.r.cloudfront.net
August 29, 2016

server-54-192-19-208.iad12.r.cloudfront.net
August 29, 2016

server-52-84-125-44.iad16.r.cloudfront.net
August 27, 2016

server-52-84-125-189.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-37.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-33.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-22.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-239.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-231.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-200.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-246.iad16.r.cloudfront.net
July 22, 2016

server-52-84-125-245.iad16.r.cloudfront.net
July 22, 2016

server-52-84-125-185.iad16.r.cloudfront.net
July 22, 2016

server-52-85-131-15.iad53.r.cloudfront.net
July 20, 2016

server-52-85-131-215.iad53.r.cloudfront.net
July 20, 2016

server-52-85-131-9.iad53.r.cloudfront.net
July 18, 2016

server-52-85-131-180.iad53.r.cloudfront.net
July 18, 2016

server-52-85-131-133.iad53.r.cloudfront.net
July 18, 2016

server-52-85-131-86.iad53.r.cloudfront.net
July 18, 2016

server-52-85-131-75.iad53.r.cloudfront.net
July 18, 2016

server-52-85-131-60.iad53.r.cloudfront.net
July 18, 2016

server-52-84-125-192.iad16.r.cloudfront.net
July 5, 2016

server-52-84-125-190.iad16.r.cloudfront.net
July 5, 2016

server-52-84-125-165.iad16.r.cloudfront.net
July 5, 2016

server-52-84-125-150.iad16.r.cloudfront.net
July 5, 2016

 
Showing 30 of 249 IP Addresses

File downloads found at URLs served by download.easydriverpro.net.

4 / 68      (PUP)

The following 473 files have been seen to comunicate with download.easydriverpro.net in live environments.

 
Latest 20 of 1,063 files

URL:
http://download.easydriverpro.net/

Network:
Amazon Cloudfront

Web server:
AmazonS3