www.holdmyreq.co

BRSOFTWARELLC

Domain Information

The domain www.holdmyreq.co registered by BRSOFTWARELLC was initially registered in March of 2015 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
NAMECHEAP, INC.

Server location:
Virginia, United States (US)

Create date:
Tuesday, March 10, 2015

Expires date:
Wednesday, March 9, 2016

Updated date:
Friday, March 18, 2016

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (77% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.TECHALPHA.Installer (M), PUP.Starglobe.Installer (M), PUP.Adload.Devstation.Installer (M), PUP.Gencolabs.Installer (M), PUP.Tecnolab.Installer (M), PUP.Starglob.Installer (M), PUP.TECHALPH.Installer (M), PUP (M)
70.83%

VIPRE Antivirus
Threat.4785227, Amonetize
33.33%

Emsisoft Anti-Malware
Gen:Heur.Conjar, Adware.Adload
33.33%

avast!
Malware-gen, Downloader-ACE [PUP], NSIS:Downloader-ACE [PUP], Win32:Malware-gen
33.33%

AVG
Downloader.NSIS
29.17%

Sophos
PUA 'AdLoad' (of type Adware), AdLoad (PUA)
29.17%

Kaspersky
Trojan-Downloader.Win32.Genome, UDS:DangerousObject.Multi.Generic, HEUR:Trojan-Downloader.Win32.Generic
25.00%

MicroWorld eScan
Gen:Heur.Conjar.1, Adware.Adload.G
25.00%

Arcabit
Trojan.Conjar.1, Adware.Adload.G
25.00%

Bitdefender
Gen:Heur.Conjar.1, Adware.Adload.G
25.00%

Avira AntiVirus
TR/Dldr.Adload.66013, ADWARE/Adware.Gen7
25.00%

G Data
Gen:Heur.Conjar, Adware.Adload
25.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
25.00%

Fortinet FortiGate
Adware/AdloadAM
25.00%

F-Secure
Adware.Adload.G, Gen:Heur.Conjar.1
20.83%

The domain www.holdmyreq.co has been seen to resolve to the following 6 IP addresses.

ec2-52-201-52-18.compute-1.amazonaws.com
April 15, 2016

ec2-52-20-13-20.compute-1.amazonaws.com
April 15, 2016

ec2-52-86-210-34.compute-1.amazonaws.com
April 2, 2016

ec2-52-3-127-100.compute-1.amazonaws.com
April 2, 2016

January 31, 2016

June 19, 2015

File downloads found at URLs served by www.holdmyreq.co.

1 / 68      (PUP)
http://www.holdmyreq.co/ids/id55/.../Iniciar-Download.exe  (1e9b651f56546367e23e04bee3d51e2c)

URL:
http://www.holdmyreq.co/

Google Analytics:
UA-12529737

Title:
“holdmyreq.co - domain expired”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx