www.autojuly109-ml-download.biz

WhoisGuard, Inc.  (Proxy Registrant)

Domain Information

The domain www.autojuly109-ml-download.biz is registered by proxy through ENOM, INC. and was originally registered in April of 2015. Currently this domain has been known to host various forms of malware. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Thursday, April 30, 2015

Expires date:
Friday, April 29, 2016

Updated date:
Thursday, April 30, 2015

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP, Adware.Amonetize.ET (M)
100.00%

Kaspersky
not-a-virus:AdWare.Win32.Amonetize, not-a-virus:HEUR:AdWare.Win32.Generic
50.00%

Bkav FE
HW32.Packed
50.00%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
41.67%

Avira AntiVirus
ADWARE/Amonetize.604160.6, ADWARE/Amonetize.806416, ADWARE/Amonetize.807936, ADWARE/Amonetize.Gen7
41.67%

AVG
Adware BundleApp.HEP, Inject2
41.67%

Baidu Antivirus
PUA.Win32.Amonetize
41.67%

McAfee
Trojan.Artemis!B78D5AF9EC5E, Trojan.Artemis!11DDEDF9D8CB, Artemis!59A4B48D024F, Artemis!920CB99C3E90
33.33%

Panda Antivirus
Generic Suspicious, Trj/Genetic.gen
33.33%

ESET NOD32
Win32/Amonetize.FI potentially unwanted (variant), Win32/Amonetize.FO potentially unwanted (variant)
33.33%

Dr.Web
Trojan.Amonetize.3786, Trojan.MulDrop6.5559
25.00%

Malwarebytes
PUP.Optional.Amonetize.A, PUP.Optional.Amonitize
25.00%

MicroWorld eScan
Gen:Variant.Mikey.17037, Gen:Application.Imonetize.2
25.00%

Zillya! Antivirus
Adware.Amonetize.Win32.4323, Adware.Amonetize.Win32.5029
25.00%

Arcabit
Trojan.Mikey.D428D, Application.Imonetize.2
25.00%

The domain www.autojuly109-ml-download.biz has been seen to resolve to the following 2 IP addresses.

May 16, 2016

ec2-54-83-193-104.compute-1.amazonaws.com
June 26, 2015

File downloads found at URLs served by www.autojuly109-ml-download.biz.

URL:
http://www.autojuly109-ml-download.biz/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Apache/2.2.15 (Red Hat) (PHP/5.3.3)