The domain get.downserver5.com registered by OutBrowse was initially registered in April of 2014 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
GODADDY.COM, LLC
Create date:
Sunday, April 20, 2014
Expires date:
Wednesday, April 20, 2016
Updated date:
Sunday, April 26, 2015
Google Safe Browsing:
malware
Scanner detections:
Detections (67% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Outbrowse, PUP.OutBrowse (M), PUP.Outbrowse.StartPlaying.Bundler (M), PUP.Outbrowse.BonDoNjOv.Bundler (M), PUP.Outbrowse.BonDoNjO.Bundler (M), PUP.Outbrowse.StartPla.Bundler (M)
66.67%
ESET NOD32
Win32/OutBrowse.BU potentially unwanted application, Win32/OutBrowse.BZ potentially unwanted application
50.00%
McAfee
Program.Adware-OutBrowse.e, Program.Adware-OutBrowse.h, Trojan.Adware-OutBrowse.h, Trojan.Artemis!F390E1031DA7
50.00%
Dr.Web
infected with Trojan.OutBrowse.100, infected with Trojan.OutBrowse.1215, infected with Trojan.OutBrowse.1574, infected with Trojan.OutBrowse.1611
50.00%
Sophos
OutBrowse Revenyou, PUA 'OutBrowse Revenyou', Generic PUA BO (PUA), Generic PUA OB (PUA)
50.00%
VIPRE Antivirus
Threat.4150696, OutBrowse
41.67%
K7 AntiVirus
Trojan , Unwanted-Program
41.67%
Comodo Security
Application.Win32.AltBrowse.HY, Application.Win32.OutBrowse.AZ, ApplicUnwnt.Win32.OutBrowse.AM
41.67%
Avira AntiVirus
PUA/Outbrowse.Gen
41.67%
G Data
Gen:Variant.Application.Bundler.Outbrowse, Win32.Adware.Outbrowse, Win32.Application.OutBrowse.AQ
41.67%
Fortinet FortiGate
Riskware/OutBrowse, Adware/OutBrowse
41.67%
Kaspersky
not-a-virus:HEUR:AdWare.Win32.OutBrowse, not-a-virus:AdWare.Win32.OutBrowse
41.67%
Agnitum Outpost
PUA.OutBrowse
33.33%
Clam AntiVirus
Win.Adware.Outbrowse-1046, Win.Adware.Outbrowse-1128
33.33%
The domain get.downserver5.com has been seen to resolve to the following 19 IP addresses.
ec2-50-19-244-143.compute-1.amazonaws.com
April 17, 2016
ec2-54-225-72-141.compute-1.amazonaws.com
April 2, 2016
ec2-54-225-153-30.compute-1.amazonaws.com
February 29, 2016
ec2-107-20-138-96.compute-1.amazonaws.com
February 29, 2016
ec2-54-225-222-50.compute-1.amazonaws.com
February 10, 2016
ec2-23-23-109-139.compute-1.amazonaws.com
February 10, 2016
ec2-54-83-204-208.compute-1.amazonaws.com
December 5, 2015
ec2-54-235-141-90.compute-1.amazonaws.com
December 5, 2015
ec2-54-197-249-79.compute-1.amazonaws.com
December 5, 2015
ec2-54-235-139-218.compute-1.amazonaws.com
October 26, 2015
ec2-54-221-237-19.compute-1.amazonaws.com
October 26, 2015
ec2-107-20-176-109.compute-1.amazonaws.com
October 26, 2015
ec2-54-243-184-119.compute-1.amazonaws.com
October 26, 2015
ec2-50-16-189-166.compute-1.amazonaws.com
October 26, 2015
ec2-107-22-164-116.compute-1.amazonaws.com
October 26, 2015
ec2-23-21-67-254.compute-1.amazonaws.com
October 12, 2015
ec2-54-225-71-32.compute-1.amazonaws.com
October 12, 2015
ec2-23-21-212-252.compute-1.amazonaws.com
October 12, 2015
ec2-107-22-237-67.compute-1.amazonaws.com
May 5, 2015
File downloads found at URLs served by get.downserver5.com.
The following file have been seen to comunicate with get.downserver5.com in live environments.
URL:
http://get.downserver5.com/
Network:
Amazon Web Services (AWS), running an EC2 instance
Web server:
Microsoft-IIS/8.0 (ASP.NET) (Version: 4.0.30319)