www.easytransitnow.com

The Management Group II

Domain Information

The domain www.easytransitnow.com registered by The Management Group II was initially registered in February of 2016 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Registrar:
SOARING EAGLE DOMAINS, LLC

Server location:
Quebec, Canada (CA)

Create date:
Monday, February 29, 2016

Expires date:
Tuesday, February 28, 2017

Updated date:
Monday, February 29, 2016

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Crawler.S, PUP.Crawler.Installer (M), PUP.Crawler.CrawlerG.Installer (M), PUP.Crawler (M)
100.00%

Dr.Web
riskware program Program.Unwanted.33, riskware program Program.Unwanted.45
66.67%

ESET NOD32
Win32/Toolbar.Crawler.B potentially unwanted application, Detection.Undefined
66.67%

Clam AntiVirus
Win.Adware.PCFixSpeed
66.67%

Kaspersky
not-a-virus:WebToolbar.Win32.Agent, not-a-virus:WebToolbar.Win32.CrawBar
33.33%

IKARUS anti.virus
PUA.Toolbar.Crawler, not-a-virus:WebToolbar.CrawBar
33.33%

G Data
Win32.Application.Crawler
26.67%

Bkav FE
W32.HfsAdware
26.67%

VIPRE Antivirus
Threat.4150696
6.67%

Malwarebytes
PUP.Optional.CrawlerTBB
6.67%

AVG
Adware BundleApp
6.67%

K7 AntiVirus
Unwanted-Program
6.67%

Avira AntiVirus
ADWARE/Toolbar.2306096
6.67%

The domain www.easytransitnow.com has been seen to resolve to the following 5 IP addresses.

ns513839.ip-167-114-156.net
May 17, 2016

May 16, 2016

April 6, 2016

ip-50-63-202-34.ip.secureserver.net
January 4, 2016

host-20-33-115-66.ciberlynx.net
August 26, 2014

File downloads found at URLs served by www.easytransitnow.com.

1 / 68      (PUP)
http://www.easytransitnow.com/.../PublicTransitSetup.exe  (3360d305e87870e950a243055c93b320)

1 / 68      (PUP)
http://www.easytransitnow.com/.../PublicTransitSetup.exe  (3df38c4d835ab36a2cb46ba0e5518857)

4 / 68      (PUP)

1 / 68      (Adware)
http://www.easytransitnow.com/.../PublicTransitSetup.exe  (329945f20dde8ba1710e8ed24f03d695)

1 / 68      (Adware)
http://www.easytransitnow.com/.../PublicTransitSetup.exe  (4adbcbfb48202eefc1092df242187e71)

1 / 68      (PUP)
http://www.easytransitnow.com/.../PublicTransitSetup.exe  (43e92a75676c1c026c3eafdb7431a279)

4 / 68      (PUP)

4 / 68      (PUP)

13 / 68    (PUP)
http://www.easytransitnow.com/.../PublicTransitSetup.exe  (df3ba3b4e0563f2e3e845b1a67204f00)

8 / 68      (PUP)
http://www.easytransitnow.com/.../PublicTransitSetup.exe  (45481236d6854b512ce1f9b602070a66)

8 / 68      (PUP)
http://www.easytransitnow.com/.../PublicTransitSetup.exe  (94ea135bca26e3faca71cee8313b9ad9)

8 / 68      (PUP)
http://www.easytransitnow.com/.../PublicTransitSetup.exe  (8fdc338d40e0c0b9c587cbabc36ef67e)

6 / 68      (PUP)
http://www.easytransitnow.com/.../PublicTransitSetup.exe  (5545b5fe2f511967053224163376930e)

4 / 68      (PUP)

4 / 68      (PUP)
http://www.easytransitnow.com/.../PublicTransitSetup.exe  (973326fec148f2bf08e44b68288e6f97)

The following 38 files have been seen to comunicate with www.easytransitnow.com in live environments.

 
Latest 20 of 44 files

URL:
http://www.easytransitnow.com/

Title:
“easytransitnow.com -&nbspThis website is for sale! -&nbspeasytransitnow Resources and Information.”

Description:
“This”

Web server:
Apache (PHP/5.3.3-7+squeeze28)

Facebook:
Likes:  62
Shares:  232
Comments:  58

Statistics are for the previous month.