download.startsdownload.com

Kim Watson

Domain Information

The domain download.startsdownload.com registered by Kim Watson was initially registered in October of 2012 through DOMAIN.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Seattle, Washington within the United States. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
DOMAIN.COM, LLC

Server location:
Washington, United States (US)

Create date:
Monday, October 15, 2012

Expires date:
Saturday, October 15, 2016

Updated date:
Wednesday, September 30, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (90% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.DownloadShield.Installer (M)
90.00%

VIPRE Antivirus
DownloadShield
60.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
60.00%

AVG
MultiBundle
60.00%

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
50.00%

McAfee
Artemis!5D1EE232CB3E, Artemis!4CF599E48944, Artemis!DF664BAA27D8, Artemis!7AE6FA0865F6
40.00%

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen, HEUR/QVM42.0.Malware.Gen
30.00%

Bkav FE
W32.HfsAdware
30.00%

NANO AntiVirus
Riskware.Nsis.Dloader.dvvnkj
30.00%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A
10.00%

F-Secure
Application:W32/Generic.70053c248f!Online
10.00%

The domain download.startsdownload.com has been seen to resolve to the following 63 IP addresses.

server-52-84-125-253.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-249.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-230.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-218.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-108.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-69.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-57.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-4.iad16.r.cloudfront.net
August 23, 2016

server-52-85-131-124.iad53.r.cloudfront.net
May 25, 2016

server-52-85-131-109.iad53.r.cloudfront.net
May 25, 2016

server-52-85-131-21.iad53.r.cloudfront.net
May 25, 2016

server-52-85-131-233.iad53.r.cloudfront.net
May 25, 2016

server-52-85-131-221.iad53.r.cloudfront.net
May 25, 2016

server-52-85-131-135.iad53.r.cloudfront.net
May 25, 2016

server-52-85-142-4.iad12.r.cloudfront.net
May 16, 2016

server-52-85-142-242.iad12.r.cloudfront.net
May 16, 2016

server-52-85-142-135.iad12.r.cloudfront.net
May 16, 2016

server-52-85-142-95.iad12.r.cloudfront.net
May 16, 2016

server-52-85-142-93.iad12.r.cloudfront.net
May 16, 2016

server-52-85-142-88.iad12.r.cloudfront.net
May 16, 2016

server-52-85-142-28.iad12.r.cloudfront.net
May 16, 2016

server-52-85-142-23.iad12.r.cloudfront.net
May 16, 2016

server-52-85-131-43.iad53.r.cloudfront.net
April 21, 2016

server-52-85-131-102.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-101.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-37.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-36.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-247.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-242.iad53.r.cloudfront.net
April 16, 2016

server-52-85-131-198.iad53.r.cloudfront.net
April 16, 2016

 
Showing 30 of 63 IP Addresses

File downloads found at URLs served by download.startsdownload.com.

7 / 68      (Adware)
http://download.startsdownload.com/Minecraft_Setup.exe  (4cf599e489440a0b48301284d5e7ab83)

6 / 68      (Adware)
http://download.startsdownload.com/Minecraft_Setup.exe  (df664baa27d83e925d4e7a316c57d31c)

6 / 68      (Adware)
http://download.startsdownload.com/Minecraft_Setup.exe  (5d1ee232cb3e7589cf6320416abda720)

1 / 68      (Adware)
http://download.startsdownload.com/Minecraft_game.exe  (cbf0eedd44b8be75240672fb6b7868f9)

2 / 68      (false positives)

2 / 68      (false positives)

1 / 68      (Adware)
http://download.startsdownload.com/Minecraft_Setup.exe  (c0ba162f94e8419e1fe137cd09709143)

9 / 68      (Adware)
http://download.startsdownload.com/Minecraft_Setup.exe  (7ae6fa0865f6596ba9551352803a4304)

1 / 68      (Adware)
http://download.startsdownload.com/Minecraft_Setup.exe  (3e78ab5ca903b7dec6a755fb5d3cf5a9)

7 / 68      (Adware)
http://download.startsdownload.com/Minecraft_Setup.exe  (96ba20688a8ba3c4c831d514c53511ec)

7 / 68      (Adware)
http://download.startsdownload.com/Minecraft_Setup.exe  (81d6dd6347e6df065b40f08fcbabedf2)

The following 38 files have been seen to comunicate with download.startsdownload.com in live environments.

 
Latest 20 of 90 files

URL:
http://download.startsdownload.com/

Network:
Amazon Cloudfront

Web server:
AmazonS3