get.downserver5.com

OutBrowse

Domain Information

The domain get.downserver5.com registered by OutBrowse was initially registered in April of 2014 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
GODADDY.COM, LLC

Create date:
Sunday, April 20, 2014

Expires date:
Wednesday, April 20, 2016

Updated date:
Sunday, April 26, 2015

Root domain:

Google Safe Browsing:
malware

Scanner detections:
Detections  (67% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Outbrowse, PUP.OutBrowse (M), PUP.Outbrowse.StartPlaying.Bundler (M), PUP.Outbrowse.BonDoNjOv.Bundler (M), PUP.Outbrowse.BonDoNjO.Bundler (M), PUP.Outbrowse.StartPla.Bundler (M)
66.67%

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application, Win32/OutBrowse.BZ potentially unwanted application
50.00%

McAfee
Program.Adware-OutBrowse.e, Program.Adware-OutBrowse.h, Trojan.Adware-OutBrowse.h, Trojan.Artemis!F390E1031DA7
50.00%

Dr.Web
infected with Trojan.OutBrowse.100, infected with Trojan.OutBrowse.1215, infected with Trojan.OutBrowse.1574, infected with Trojan.OutBrowse.1611
50.00%

Sophos
OutBrowse Revenyou, PUA 'OutBrowse Revenyou', Generic PUA BO (PUA), Generic PUA OB (PUA)
50.00%

VIPRE Antivirus
Threat.4150696, OutBrowse
41.67%

K7 AntiVirus
Trojan , Unwanted-Program
41.67%

Comodo Security
Application.Win32.AltBrowse.HY, Application.Win32.OutBrowse.AZ, ApplicUnwnt.Win32.OutBrowse.AM
41.67%

Avira AntiVirus
PUA/Outbrowse.Gen
41.67%

G Data
Gen:Variant.Application.Bundler.Outbrowse, Win32.Adware.Outbrowse, Win32.Application.OutBrowse.AQ
41.67%

Fortinet FortiGate
Riskware/OutBrowse, Adware/OutBrowse
41.67%

AVG
Downloader
41.67%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.OutBrowse, not-a-virus:AdWare.Win32.OutBrowse
41.67%

Agnitum Outpost
PUA.OutBrowse
33.33%

Clam AntiVirus
Win.Adware.Outbrowse-1046, Win.Adware.Outbrowse-1128
33.33%

The domain get.downserver5.com has been seen to resolve to the following 19 IP addresses.

ec2-50-19-244-143.compute-1.amazonaws.com
April 17, 2016

ec2-54-225-72-141.compute-1.amazonaws.com
April 2, 2016

ec2-54-225-153-30.compute-1.amazonaws.com
February 29, 2016

ec2-107-20-138-96.compute-1.amazonaws.com
February 29, 2016

ec2-54-225-222-50.compute-1.amazonaws.com
February 10, 2016

ec2-23-23-109-139.compute-1.amazonaws.com
February 10, 2016

ec2-54-83-204-208.compute-1.amazonaws.com
December 5, 2015

ec2-54-235-141-90.compute-1.amazonaws.com
December 5, 2015

ec2-54-197-249-79.compute-1.amazonaws.com
December 5, 2015

ec2-54-235-139-218.compute-1.amazonaws.com
October 26, 2015

ec2-54-221-237-19.compute-1.amazonaws.com
October 26, 2015

ec2-107-20-176-109.compute-1.amazonaws.com
October 26, 2015

ec2-54-243-184-119.compute-1.amazonaws.com
October 26, 2015

ec2-50-16-189-166.compute-1.amazonaws.com
October 26, 2015

ec2-107-22-164-116.compute-1.amazonaws.com
October 26, 2015

ec2-23-21-67-254.compute-1.amazonaws.com
October 12, 2015

ec2-54-225-71-32.compute-1.amazonaws.com
October 12, 2015

ec2-23-21-212-252.compute-1.amazonaws.com
October 12, 2015

ec2-107-22-237-67.compute-1.amazonaws.com
May 5, 2015

File downloads found at URLs served by get.downserver5.com.

The following file have been seen to comunicate with get.downserver5.com in live environments.

URL:
http://get.downserver5.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Microsoft-IIS/8.0 (ASP.NET) (Version: 4.0.30319)