jdownloader.downloadhosters.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain jdownloader.downloadhosters.com is registered by proxy through ENOM, INC. and was originally registered in April of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Wednesday, April 10, 2013

Expires date:
Friday, April 10, 2015

Updated date:
Tuesday, March 11, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.InstallCore.A
100.00%

Agnitum Outpost
PUA.InstallCore
100.00%

F-Prot
W32/InstallCore.R3.gen
100.00%

SUPERAntiSpyware
PUP.InstallCore/Variant
100.00%

Comodo Security
ApplicUnwnt
100.00%

Dr.Web
Trojan.Packed.24524
100.00%

VIPRE Antivirus
InstallCore
100.00%

Avira AntiVirus
ADWARE/InstallCore.Gen7
100.00%

Sophos
Install Core
100.00%

Vba32 AntiVirus
Downware.InstallCore
100.00%

ESET NOD32
Win32/InstallCore.CH (variant)
100.00%

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
100.00%

AVG
Skodna.Generic_c
100.00%

The domain jdownloader.downloadhosters.com has been seen to resolve to the following 8 IP addresses.

server-204-246-169-164.jfk1.r.cloudfront.net
April 23, 2014

server-204-246-169-40.jfk1.r.cloudfront.net
April 23, 2014

server-54-230-39-179.jfk1.r.cloudfront.net
April 23, 2014

server-54-230-39-211.jfk1.r.cloudfront.net
April 23, 2014

server-54-230-37-218.jfk1.r.cloudfront.net
April 23, 2014

server-54-230-37-120.jfk1.r.cloudfront.net
April 23, 2014

server-54-230-38-112.jfk1.r.cloudfront.net
April 23, 2014

server-54-230-39-229.jfk1.r.cloudfront.net
April 23, 2014

File downloads found at URLs served by jdownloader.downloadhosters.com.

13 / 68    (PUP)

The following 2 files have been seen to comunicate with jdownloader.downloadhosters.com in live environments.

URL:
http://jdownloader.downloadhosters.com/

Google Analytics:
UA-44261306

Title:
“Download JDownloader”

Network:
Amazon Cloudfront

Web server:
AmazonS3