w40.am15.net

AD Solution Media Associates

Domain Information

The domain w40.am15.net registered by AD Solution Media Associates was initially registered in November of 2012 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Nuremberg, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Bayern, Germany (DE)

Create date:
Thursday, November 15, 2012

Expires date:
Tuesday, November 15, 2016

Updated date:
Monday, April 4, 2016

ASN:
AS24940 HETZNER-AS Hetzner Online GmbH, DE

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.Amonetize.AS
100.00%

K7 AntiVirus
Riskware
100.00%

Dr.Web
Adware.Downware.1339
100.00%

Sophos
Amonetize
100.00%

ESET NOD32
Win32/Amonetize (variant)
100.00%

Reason Heuristics
PUP.Installer.Amonetizeltd.b
100.00%

The domain w40.am15.net has been seen to resolve to the following IP address.

static.44.120.76.144.clients.your-server.de
May 20, 2016

File downloads found at URLs served by w40.am15.net.

6 / 68      (Adware)
http://w40.am15.net/bn3.php?k=f591ff72345b7b91623260b32fc88a85  (launcher__2705_i29401044_il552038.exe)

The following 3 files have been seen to comunicate with w40.am15.net in live environments.

URL:
http://w40.am15.net/

Title:
“Advmaker.net”

Description:
“Advmaker.net”

SSL certificate subject:
CN=*.am15.net, OU=EssentialSSL Wildcard, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
nginx (PHP/5.6.10-1+deb.sury.org~trusty+1)