downloads.ezdownload.co

WhoisGuard, Inc.  (Proxy Registrant)

Domain Information

The domain downloads.ezdownload.co is registered by proxy through NAMECHEAP, INC. and was originally registered in July of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Digital Ocean, Inc. network.
Registrar:
NAMECHEAP, INC.

Server location:
New York, United States (US)

Create date:
Wednesday, July 22, 2015

Expires date:
Thursday, July 21, 2016

Updated date:
Thursday, July 23, 2015

ASN:
AS393406 DIGITALOCEAN-ASN-NY3 - Digital Ocean, Inc.,US

Root domain:

Scanner detections:
Detections  (78% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Vittalia.Software.Installer (M), PUP.Air Software.Download.Bundler (M), PUP.Air Software (M), PUP.Vittalia (M)
97.50%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A
2.50%

F-Secure
Application:W32/Generic.70053c248f!Online
2.50%

The domain downloads.ezdownload.co has been seen to resolve to the following 11 IP addresses.

ec2-52-20-105-106.compute-1.amazonaws.com
September 14, 2016

ec2-52-1-51-167.compute-1.amazonaws.com
August 24, 2016

ec2-52-7-179-5.compute-1.amazonaws.com
August 12, 2016

ec2-52-7-155-18.compute-1.amazonaws.com
August 12, 2016

ec2-54-172-237-31.compute-1.amazonaws.com
August 12, 2016

ec2-52-73-0-213.compute-1.amazonaws.com
July 30, 2016

ec2-54-173-202-137.compute-1.amazonaws.com
July 30, 2016

ec2-54-152-60-180.compute-1.amazonaws.com
July 30, 2016

parkingpage.namecheap.com
July 22, 2016

fd-03-do-e-ny-3.gtdlrfwd.com
October 19, 2015

useast.gtdlrfwd.com
October 7, 2015

File downloads found at URLs served by downloads.ezdownload.co.

The following 16 files have been seen to comunicate with downloads.ezdownload.co in live environments.

URL:
http://downloads.ezdownload.co/

Title:
“Welcome to nginx!”

Web server:
nginx/1.4.6 (Ubuntu)