download.boostmypc.com

BRANDON ABBEY

Domain Information

The domain download.boostmypc.com registered by BRANDON ABBEY was initially registered in August of 2004 through ENOM, INC.. Currently this domain has been known to host various forms of malware. The hosted servers are located in Dulles, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Thursday, August 19, 2004

Expires date:
Saturday, August 19, 2017

Updated date:
Wednesday, July 8, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Malware distribution  (86% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Installer.EnergizerSoftechPvt, Optional.BoostMyPC.SpeedbitTechnology.Installer.Meta (L), Optional.BoostMyPC.Speedbit.Installer.Meta (L)
100.00%

McAfee
Artemis!25DFB25BCC7E
50.00%

Dr.Web
Trojan.DownLoader11.45558
33.33%

Sophos
Energizer Softech Installer
16.67%

The domain download.boostmypc.com has been seen to resolve to the following 40 IP addresses.

server-52-85-131-57.iad53.r.cloudfront.net
May 16, 2016

server-52-85-131-21.iad53.r.cloudfront.net
May 16, 2016

server-52-85-131-204.iad53.r.cloudfront.net
May 16, 2016

server-52-85-131-178.iad53.r.cloudfront.net
May 16, 2016

server-52-85-131-159.iad53.r.cloudfront.net
May 16, 2016

server-52-85-131-131.iad53.r.cloudfront.net
May 16, 2016

server-52-85-131-120.iad53.r.cloudfront.net
May 16, 2016

server-52-85-131-61.iad53.r.cloudfront.net
May 16, 2016

server-52-85-142-33.iad12.r.cloudfront.net
May 15, 2016

server-52-85-142-10.iad12.r.cloudfront.net
May 15, 2016

server-52-85-142-207.iad12.r.cloudfront.net
May 15, 2016

server-52-85-142-172.iad12.r.cloudfront.net
May 15, 2016

server-52-85-142-109.iad12.r.cloudfront.net
May 15, 2016

server-52-85-142-91.iad12.r.cloudfront.net
May 15, 2016

server-52-85-142-64.iad12.r.cloudfront.net
May 15, 2016

server-52-85-142-40.iad12.r.cloudfront.net
May 15, 2016

server-54-192-194-97.iad53.r.cloudfront.net
October 12, 2015

server-54-192-194-79.iad53.r.cloudfront.net
October 12, 2015

server-54-230-195-193.iad53.r.cloudfront.net
October 12, 2015

server-54-230-195-103.iad53.r.cloudfront.net
October 12, 2015

server-54-230-192-198.iad53.r.cloudfront.net
October 12, 2015

server-54-230-192-27.iad53.r.cloudfront.net
October 12, 2015

server-54-230-192-12.iad53.r.cloudfront.net
October 12, 2015

server-54-192-194-142.iad53.r.cloudfront.net
October 12, 2015

server-54-230-194-81.iad53.r.cloudfront.net
August 12, 2015

server-54-230-193-246.iad53.r.cloudfront.net
August 12, 2015

server-54-230-193-33.iad53.r.cloudfront.net
August 12, 2015

server-54-192-194-146.iad53.r.cloudfront.net
August 12, 2015

server-54-192-193-52.iad53.r.cloudfront.net
August 12, 2015

server-54-192-193-14.iad53.r.cloudfront.net
August 12, 2015

 
Showing 30 of 40 IP Addresses

File downloads found at URLs served by download.boostmypc.com.

0 / 68
http://download.boostmypc.com/BoostMyPCsetup.exe  (67e7f69d2c1a8f0d3cdd53facbae793e)

1 / 68      (Malware)
http://download.boostmypc.com/BoostMyPCsetup.exe  (8e1097468d57d629e278b9162e0fa682)

1 / 68      (Malware)
http://download.boostmypc.com/BoostMyPCsetup.exe  (0dc83b84666c7aa09ec786049e57048d)

1 / 68      (Malware)
http://download.boostmypc.com/BoostMyPCsetup.exe  (45cbda29f91a241818255aa603bd3096)

1 / 68      (Malware)
http://download.boostmypc.com/BoostMyPCsetup.exe  (46268f4ea06e077f1417ab0d450c44a2)

8 / 68      (PUP)

1 / 68      (Malware)
http://download.boostmypc.com/BoostMyPCsetup.exe  (9ecbccc0ee6d5cc01d50679e6b392e50)

The following 27 files have been seen to comunicate with download.boostmypc.com in live environments.

 
Latest 20 of 44 files

URL:
http://download.boostmypc.com/

Network:
Amazon Cloudfront

Web server:
AmazonS3