downprov7.downloadfasteasy.com

Whois Privacy Corp.

Domain Information

The domain downprov7.downloadfasteasy.com registered by Whois Privacy Corp. was initially registered in November of 2014 through TLD REGISTRAR SOLUTIONS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
TLD REGISTRAR SOLUTIONS LTD

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Monday, November 10, 2014

Expires date:
Thursday, November 10, 2016

Updated date:
Wednesday, November 4, 2015

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Ukra2006.?, PUP.Ukra2006.u, PUP.Ukra2006.o, PUP.Ukra2006.y, PUP.Ukra2006.x, PUP.Ukra2006.b, PUP.Ukra2006.i, PUP.Bundler.Amonetize, Threat.Amonetize.Bundler, PUP.Amonetize.Ukra2006.Bundler (M)
87.88%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
54.55%

Dr.Web
Trojan.Amonetize.12, infected with Trojan.Amonetize.353, Trojan.Amonetize.2263, infected with Trojan.Amonetize.2503, - infected container c:\users\test\appdata\local\temp\edab403024ac20eda004c796553c67981975e737\scri
54.55%

Clam AntiVirus
Win.Adware.Amonetize-511, Win.Adware.Amonetize-703
48.48%

G Data
NSIS.Application.Crypted
48.48%

AVG
Generic
48.48%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize, not-a-virus:AdWare.Win32.Amonetize, UDS:DangerousObject.Multi.Generic
42.42%

Avira AntiVirus
Adware/Amonetize.kpa, Adware/AgentCV.A.119, ADWARE/AgentCV.A.119
39.39%

Trend Micro House Call
Suspici.1CC0D1BF, TROJ_GEN.R0C1H07LN14, TROJ_GE.28D9CDA2, TROJ_GEN.R0C1H07A415
39.39%

Sophos
PUA 'Amonetize', Generic PUA HI
36.36%

ESET NOD32
Win32/Amonetize.CL potentially unwanted application, Win32/Amonetize.CW potentially unwanted application, Win32/Amonetize.CT potentially unwanted application
33.33%

McAfee
Artemis!8F00B3F9F161, Artemis!CB3AB32609D3
30.30%

Panda Antivirus
Generic Suspicious
27.27%

avast!
Rootkit-gen [Rtk], Malware-gen, OutBrowse-AH [PUP], Win32:Amonetize-KK [PUP], Win32:OutBrowse-AH [PUP], Win32:PUP-gen [PUP]
24.24%

Baidu Antivirus
Adware.Win32.Amonetize, PUA.Win32.Amonetize
24.24%

The domain downprov7.downloadfasteasy.com has been seen to resolve to the following IP address.

unallocated.barefruit.co.uk
May 14, 2015

File downloads found at URLs served by downprov7.downloadfasteasy.com.

23 / 68    (PUP)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

4 / 68      (PUP)

5 / 68      (PUP)

4 / 68      (PUP)

1 / 68      (Adware)

1 / 68      (Adware)

15 / 68    (Adware)

17 / 68    (Adware)

15 / 68    (Adware)

11 / 68    (Adware)

 
Latest 30 of 36 download URLs

The following 230 files have been seen to comunicate with downprov7.downloadfasteasy.com in live environments.

 
Latest 20 of 230 files