The domain downprov7.downloadfasteasy.com registered by Whois Privacy Corp. was initially registered in November of 2014 through TLD REGISTRAR SOLUTIONS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrant:
Whois Privacy Corp.
Registrar:
TLD REGISTRAR SOLUTIONS LTD
Server location:
Northern Ireland, United Kingdom (GB)
Create date:
Monday, November 10, 2014
Expires date:
Thursday, November 10, 2016
Updated date:
Wednesday, November 4, 2015
Scanner detections:
Detections (94% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Ukra2006.?, PUP.Ukra2006.u, PUP.Ukra2006.o, PUP.Ukra2006.y, PUP.Ukra2006.x, PUP.Ukra2006.b, PUP.Ukra2006.i, PUP.Bundler.Amonetize, Threat.Amonetize.Bundler, PUP.Amonetize.Ukra2006.Bundler (M)
87.88%
VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
54.55%
Dr.Web
Trojan.Amonetize.12, infected with Trojan.Amonetize.353, Trojan.Amonetize.2263, infected with Trojan.Amonetize.2503, - infected container
c:\users\test\appdata\local\temp\edab403024ac20eda004c796553c67981975e737\scri
54.55%
Clam AntiVirus
Win.Adware.Amonetize-511, Win.Adware.Amonetize-703
48.48%
G Data
NSIS.Application.Crypted
48.48%
Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize, not-a-virus:AdWare.Win32.Amonetize, UDS:DangerousObject.Multi.Generic
42.42%
Avira AntiVirus
Adware/Amonetize.kpa, Adware/AgentCV.A.119, ADWARE/AgentCV.A.119
39.39%
Trend Micro House Call
Suspici.1CC0D1BF, TROJ_GEN.R0C1H07LN14, TROJ_GE.28D9CDA2, TROJ_GEN.R0C1H07A415
39.39%
Sophos
PUA 'Amonetize', Generic PUA HI
36.36%
ESET NOD32
Win32/Amonetize.CL potentially unwanted application, Win32/Amonetize.CW potentially unwanted application, Win32/Amonetize.CT potentially unwanted application
33.33%
McAfee
Artemis!8F00B3F9F161, Artemis!CB3AB32609D3
30.30%
Panda Antivirus
Generic Suspicious
27.27%
avast!
Rootkit-gen [Rtk], Malware-gen, OutBrowse-AH [PUP], Win32:Amonetize-KK [PUP], Win32:OutBrowse-AH [PUP], Win32:PUP-gen [PUP]
24.24%
Baidu Antivirus
Adware.Win32.Amonetize, PUA.Win32.Amonetize
24.24%
The domain downprov7.downloadfasteasy.com has been seen to resolve to the following IP address.
unallocated.barefruit.co.uk
May 14, 2015
File downloads found at URLs served by downprov7.downloadfasteasy.com.
Latest 30 of 36 download URLs
The following 230 files have been seen to comunicate with downprov7.downloadfasteasy.com in live environments.