www.slow-download.com

Corp New Ventures Services

Domain Information

The domain www.slow-download.com registered by Corp New Ventures Services was initially registered in January of 2016 through GANDI SAS. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
NAMESNAP LLC

Server location:
Virginia, United States (US)

Create date:
Saturday, January 16, 2016

Expires date:
Monday, January 16, 2017

Updated date:
Saturday, January 23, 2016

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ShetefSolutionsConsulting1998.e, PUP.Installer.SVANTRANS.?, PUP.Installer.ITLGROUP.?, PUP.Installer.AMGRUP.h, PUP.Amonetize.EVROPLAST.Bundler (M), Threat.Win.Reputation.IMP
100.00%

AhnLab V3 Security
PUP/Win32.Amonetiz
87.88%

Avira AntiVirus
ADWARE/Adware.Gen2, ADWARE/Adware.Gen4, Adware/Amonetize.314368.1, TR/Crypt.ZPACK.Gen2, Adware/Amonetize.576192.2, Adware/Amonetize.576192.16
84.85%

McAfee
Artemis!2F47D2C56AD9, Artemis!8DD4F862B40E, Artemis!092124BC2924, Artemis!03267C6E2F9B, Artemis!AED5FBAC12A7, Artemis!52E6B97EA44C, Artemis!FC4183DA0CFD, Artemis!FF39F2C5F9C1, Artemis!EF3A20165C83, Artemis!F4C880259377, Artemis!F23EBE58EE48
78.79%

ESET NOD32
Win32/Amonetize.BP (variant), Win32/Amonetize.CH (variant), Win32/Amonetize.CK (variant), Win32/Amonetize.CS (variant), Win32/Amonetize.CH potentially unwanted
72.73%

AVG
Generic, Generic_r
69.70%

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
66.67%

Trend Micro House Call
TROJ_GEN.R047H09KP14, Suspicious_GEN.F47V1211, Suspicious_GEN.F47V1210, Suspicious_GEN.F47V1214, TROJ_GEN.R0C1H09LG14, TROJ_GEN.R08NH09LM14, Suspicious_GEN.F47V1224, Suspicious_GEN.F47V1226
63.64%

G Data
Gen:Variant.Adware.Strictor.68509, Gen:Variant.Adware.Netfilter, Win32.Application.Agent.9PQAZE, Trojan.GenericKD.2043180
54.55%

avast!
Win32:Amonetize-GN [PUP], Win32:Dropper-gen [Drp], Win32:Trojan-gen, Win32:Adware-gen [Adw], Win32:Malware-gen, Win32:Amonetize-HQ [PUP]
54.55%

Sophos
Generic PUA FM, Generic PUA IF, Generic PUA CB, Generic PUA JB, Generic PUA MF, Generic PUA LJ, Generic PUA PE, Generic PUA JL
51.52%

MicroWorld eScan
Gen:Variant.Adware.Strictor.68509, Gen:Variant.Adware.Netfilter.2, Trojan.GenericKD.2043180, Application.Bundler.Amonetize.AO
48.48%

Bitdefender
Gen:Variant.Adware.Strictor.68509, Gen:Variant.Adware.Netfilter.2, Trojan.GenericKD.2043180, Application.Bundler.Amonetize.AO
48.48%

NANO AntiVirus
Riskware.Win32.Amonetize.djgllc, Riskware.Win32.Amonetize.djsswg, Riskware.Win32.Amonetize.dkinix, Riskware.Win32.Amonetize.dlgsuu
48.48%

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.68509, Gen:Variant.Adware.Netfilter, Trojan.GenericKD.2043180, Trojan.GenericKD.2067331
45.45%

The domain www.slow-download.com has been seen to resolve to the following 2 IP addresses.

February 21, 2016

ec2-23-21-217-79.compute-1.amazonaws.com
December 28, 2014

File downloads found at URLs served by www.slow-download.com.

10 / 68    (Adware)
http://www.slow-download.com/download.php?version=1.1.5.26  (heroes and generals hack october 2014 no survey no password__10967_i1436325746_il311680.exe)

 
Latest 30 of 87 download URLs

The following 2 files have been seen to comunicate with www.slow-download.com in live environments.

URL:
http://www.slow-download.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Apache