The domain www.slow-download.com registered by Corp New Ventures Services was initially registered in January of 2016 through GANDI SAS. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrant:
Corp New Ventures Services
Server location:
Virginia, United States (US)
Create date:
Saturday, January 16, 2016
Expires date:
Monday, January 16, 2017
Updated date:
Saturday, January 23, 2016
ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.ShetefSolutionsConsulting1998.e, PUP.Installer.SVANTRANS.?, PUP.Installer.ITLGROUP.?, PUP.Installer.AMGRUP.h, PUP.Amonetize.EVROPLAST.Bundler (M), Threat.Win.Reputation.IMP
100.00%
AhnLab V3 Security
PUP/Win32.Amonetiz
87.88%
Avira AntiVirus
ADWARE/Adware.Gen2, ADWARE/Adware.Gen4, Adware/Amonetize.314368.1, TR/Crypt.ZPACK.Gen2, Adware/Amonetize.576192.2, Adware/Amonetize.576192.16
84.85%
McAfee
Artemis!2F47D2C56AD9, Artemis!8DD4F862B40E, Artemis!092124BC2924, Artemis!03267C6E2F9B, Artemis!AED5FBAC12A7, Artemis!52E6B97EA44C, Artemis!FC4183DA0CFD, Artemis!FF39F2C5F9C1, Artemis!EF3A20165C83, Artemis!F4C880259377, Artemis!F23EBE58EE48
78.79%
ESET NOD32
Win32/Amonetize.BP (variant), Win32/Amonetize.CH (variant), Win32/Amonetize.CK (variant), Win32/Amonetize.CS (variant), Win32/Amonetize.CH potentially unwanted
72.73%
AVG
Generic, Generic_r
69.70%
Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
66.67%
Trend Micro House Call
TROJ_GEN.R047H09KP14, Suspicious_GEN.F47V1211, Suspicious_GEN.F47V1210, Suspicious_GEN.F47V1214, TROJ_GEN.R0C1H09LG14, TROJ_GEN.R08NH09LM14, Suspicious_GEN.F47V1224, Suspicious_GEN.F47V1226
63.64%
G Data
Gen:Variant.Adware.Strictor.68509, Gen:Variant.Adware.Netfilter, Win32.Application.Agent.9PQAZE, Trojan.GenericKD.2043180
54.55%
avast!
Win32:Amonetize-GN [PUP], Win32:Dropper-gen [Drp], Win32:Trojan-gen, Win32:Adware-gen [Adw], Win32:Malware-gen, Win32:Amonetize-HQ [PUP]
54.55%
Sophos
Generic PUA FM, Generic PUA IF, Generic PUA CB, Generic PUA JB, Generic PUA MF, Generic PUA LJ, Generic PUA PE, Generic PUA JL
51.52%
MicroWorld eScan
Gen:Variant.Adware.Strictor.68509, Gen:Variant.Adware.Netfilter.2, Trojan.GenericKD.2043180, Application.Bundler.Amonetize.AO
48.48%
Bitdefender
Gen:Variant.Adware.Strictor.68509, Gen:Variant.Adware.Netfilter.2, Trojan.GenericKD.2043180, Application.Bundler.Amonetize.AO
48.48%
NANO AntiVirus
Riskware.Win32.Amonetize.djgllc, Riskware.Win32.Amonetize.djsswg, Riskware.Win32.Amonetize.dkinix, Riskware.Win32.Amonetize.dlgsuu
48.48%
Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.68509, Gen:Variant.Adware.Netfilter, Trojan.GenericKD.2043180, Trojan.GenericKD.2067331
45.45%
The domain www.slow-download.com has been seen to resolve to the following 2 IP addresses.
ec2-23-21-217-79.compute-1.amazonaws.com
December 28, 2014
File downloads found at URLs served by www.slow-download.com.
Latest 30 of 87 download URLs
The following 2 files have been seen to comunicate with www.slow-download.com in live environments.
URL:
http://www.slow-download.com/
Network:
Amazon Web Services (AWS), running an EC2 instance