download.atdheapp.com

Whois Privacy Corp.

Domain Information

The domain download.atdheapp.com registered by Whois Privacy Corp. was initially registered in December of 2012 through INTERNET.BS CORP.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the RIPE Network Coordination Centre network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Registrar:
INTERNET.BS CORP.

Server location:
Dublin City, Ireland (IE)

Create date:
Sunday, December 23, 2012

Expires date:
Wednesday, December 23, 2015

Updated date:
Monday, December 29, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.CoolMirage.Installer, PUP.CoolMirage.Installer (M)
100.00%

Dr.Web
Adware.Downware.902
50.00%

VIPRE Antivirus
Threat.4786236
50.00%

ESET NOD32
Detection.Undefined
50.00%

avast!
Downloader-TPG [PUP]
50.00%

McAfee
Program.Adware-SweetIM
50.00%

Sophos
PUA 'FT Downloader'
50.00%

Bkav FE
W32.HfsAdware
50.00%

Malwarebytes
PUP.BundleInstaller.DW
50.00%

SUPERAntiSpyware
PUP.OneClickDownloader/Variant
50.00%

K7 Gateway Antivirus
Adware
50.00%

K7 AntiVirus
Adware
50.00%

NANO AntiVirus
Riskware.Text.Adware.cuhowq
50.00%

Comodo Security
Application.Win32.MCool.A
50.00%

McAfee Web Gateway
BehavesLike.Win32.Suspicious.fc
50.00%

The domain download.atdheapp.com has been seen to resolve to the following IP address.

ec2-176-34-107-151.eu-west-1.compute.amazonaws.com
June 18, 2015

File downloads found at URLs served by download.atdheapp.com.

1 / 68      (Adware)
http://download.atdheapp.com/product_download.php?sp=2  (atdhenetappssetup(18_3c)_ch.exe)

18 / 68    (Adware)

The following 6 files have been seen to comunicate with download.atdheapp.com in live environments.