download.easyspeedpc.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain download.easyspeedpc.net is registered by proxy through GODADDY.COM, LLC and was originally registered in December of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Wednesday, December 26, 2012

Expires date:
Monday, December 26, 2016

Updated date:
Sunday, December 20, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

Dr.Web
Trojan.DownLoader11.50357, Trojan.DownLoader12.46104, Trojan.DownLoader12.18017, Trojan.DownLoader12.20853, Trojan.Siggen6.33552
65.22%

avast!
Win32:PUP-gen [PUP], Win32:Malware-gen, Win32:Dropper-gen [Drp]
56.52%

ESET NOD32
Win32/SpeedingUpMyPC.R application
52.17%

Reason Heuristics
PUP.Optional.ProbitSoftware, Win32.Generic.Installer.Meta, (M), PUP.Probit.Optional.Installer.Meta (L)
32.61%

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic, not-a-virus:Downloader.NSIS.Agent, UDS:DangerousObject.Multi.Generic
28.26%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, Downloader.Agent
19.57%

ESET NOD32
Win32/SpeedingUpMyPC
19.57%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
19.57%

AhnLab V3 Security
PUP/Win32.SpdUpMyPC
17.39%

McAfee
Artemis!07D9976CBC3F, Artemis!2031773DB239, Artemis!E4B25FF31CF2, Artemis!371D66BF58F3, Artemis!6EB4E1C19817, Artemis!E368DE9ADA19
15.22%

NANO AntiVirus
Trojan.Nsis.Downloader.dpxzgr
15.22%

Malwarebytes
PUP.Optional.EasySpeedPC.A
13.04%

Baidu Antivirus
Trojan.Win32.Downloader, Trojan.Win32.SpeedingUpMyPC, Hacktool.NSIS.Agent, PUA.Win32.SpeedingUpMyPC
13.04%

Fortinet FortiGate
Riskware/SpeedingUpMyPC
13.04%

Sophos
Generic PUA JM, Generic PUA GO, Generic PUA AD (PUA), Generic PUA CG (PUA), Generic PUA DL (PUA)
10.87%

The domain download.easyspeedpc.net has been seen to resolve to the following 233 IP addresses.

server-54-230-193-151.iad53.r.cloudfront.net
September 15, 2016

server-54-230-193-145.iad53.r.cloudfront.net
September 15, 2016

server-54-230-193-92.iad53.r.cloudfront.net
September 15, 2016

server-54-230-193-87.iad53.r.cloudfront.net
September 15, 2016

server-54-230-193-66.iad53.r.cloudfront.net
September 15, 2016

server-54-230-193-30.iad53.r.cloudfront.net
September 15, 2016

server-54-230-193-22.iad53.r.cloudfront.net
September 15, 2016

server-54-230-193-6.iad53.r.cloudfront.net
September 15, 2016

server-52-84-125-248.iad16.r.cloudfront.net
August 29, 2016

server-52-84-125-149.iad16.r.cloudfront.net
August 29, 2016

server-52-84-125-73.iad16.r.cloudfront.net
August 22, 2016

server-52-84-125-219.iad16.r.cloudfront.net
August 22, 2016

server-52-84-125-204.iad16.r.cloudfront.net
August 22, 2016

server-52-84-125-104.iad16.r.cloudfront.net
August 22, 2016

server-54-192-19-64.iad12.r.cloudfront.net
August 20, 2016

server-54-192-19-9.iad12.r.cloudfront.net
August 20, 2016

server-54-192-19-251.iad12.r.cloudfront.net
August 20, 2016

server-54-192-19-216.iad12.r.cloudfront.net
August 20, 2016

server-54-192-19-200.iad12.r.cloudfront.net
August 20, 2016

server-54-192-19-134.iad12.r.cloudfront.net
August 20, 2016

server-54-192-19-122.iad12.r.cloudfront.net
August 20, 2016

server-54-192-19-76.iad12.r.cloudfront.net
August 20, 2016

server-52-84-125-19.iad16.r.cloudfront.net
July 24, 2016

server-52-84-125-14.iad16.r.cloudfront.net
July 24, 2016

server-52-84-125-190.iad16.r.cloudfront.net
July 24, 2016

server-52-84-125-180.iad16.r.cloudfront.net
July 24, 2016

server-52-84-125-62.iad16.r.cloudfront.net
July 24, 2016

server-52-84-125-29.iad16.r.cloudfront.net
July 24, 2016

server-52-84-125-253.iad16.r.cloudfront.net
July 19, 2016

server-52-84-125-234.iad16.r.cloudfront.net
July 19, 2016

 
Showing 30 of 233 IP Addresses

File downloads found at URLs served by download.easyspeedpc.net.

1 / 68      (PUP)

5 / 68      (PUP)

1 / 68      (PUP)

15 / 68    (PUP)

4 / 68      (PUP)

The following 295 files have been seen to comunicate with download.easyspeedpc.net in live environments.

 
Latest 20 of 701 files

URL:
http://download.easyspeedpc.net/

Network:
Amazon Cloudfront

Web server:
AmazonS3