download.ytddownloader.com

Greentree Applications SRL

Domain Information

The domain download.ytddownloader.com registered by Greentree Applications SRL was initially registered in September of 2012 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Frankfurt Am Main, Hessen within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Hessen, Germany (DE)

Create date:
Tuesday, September 25, 2012

Expires date:
Sunday, September 25, 2016

Updated date:
Tuesday, December 4, 2012

ASN:
AS60781 LEASEWEB-NL LeaseWeb Netherlands B.V.,NL

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.GreentreeApplicationsSRL.N, PUP.Optional.Installer.I, PUP.Optional.GreenTreeApplicationssrl, Threat.Installer.GreenTreeApplicationssrl, Win32.Generic.Installer.Meta, Win32.Generic.GreentreeApplications.Installer.Meta, Win32.Generic.GreenTreeApplicationssrl.Installer.Meta, PUP.Greentree.YTD.Installer.Installer.Meta (M), PUP.YTD.Installer.Installer.Meta (M), PUP.GreenTree.Installer.Meta (M)
100.00%

Dr.Web
Adware.BGuard.24, Adware.Spigot.16, Adware.Downware.10494, Adware.Spigot.64, Adware.Downware.10873, Threat.Undefined
58.00%

McAfee
Artemis!77278F18ABAC, Artemis!C0841F98FF22, Artemis!8D83D7F874CA, Artemis!1816C1C5B6F4, Artemis!799D6FC1E979, Artemis!578656A0874E
54.00%

Trend Micro House Call
TROJ_GEN.R08NH07HS14, TROJ_GEN.R047H07HS14, Suspicious_GEN.F47V1117, Suspicious_GEN.F47V1125, Suspicious_GEN.F47V1218, Suspicious_GEN.F47V1115
54.00%

Bkav FE
W32.Clod5b0.Trojan, W32.Clod6c3.Trojan, W32.HfsAdware
54.00%

Malwarebytes
PUP.Optional.Spigot, PUP.Optional.APNToolBar.A
50.00%

G Data
Win32.Adware.Spigot
50.00%

ESET NOD32
Win32/Toolbar.Widgi (variant), Win32/Bundled.Toolbar.Ask (variant), Win32/Bundled.Toolbar.Ask.G potentially unsafe (variant)
50.00%

Zillya! Antivirus
Adware.RocketTab.Win32.32
50.00%

Kaspersky
not-a-virus:AdWare.MSIL.RocketTab
50.00%

IKARUS anti.virus
PUA.BrowserSafeGuard, PUA.Offer
50.00%

AVG
Downloader
50.00%

K7 AntiVirus
Trojan
50.00%

Comodo Security
ApplicUnwnt
50.00%

VIPRE Antivirus
Trojan.Win32.Generic
50.00%

The domain download.ytddownloader.com has been seen to resolve to the following 4 IP addresses.

hosted-by.leaseweb.com
June 28, 2016

hosted-by.leaseweb.com
February 27, 2016

hosted-by.leaseweb.com
January 5, 2016

hosted-by.leaseweb.com
March 13, 2015

File downloads found at URLs served by download.ytddownloader.com.

1 / 68      (PUP)
http://download.ytddownloader.com/kits/.../YTDSetup.exe  (5abf2e7e71eab0d9ea36ea61fbb15009)

1 / 68      (PUP)
http://download.ytddownloader.com/kits/.../YTDSetup.exe  (1c010db471303c0b97c6aced35298777)

1 / 68      (Malware)
http://download.ytddownloader.com/kits/.../YTDSetup.exe  (d3265565ac6c2f6ecea486d6bbab9316)

The following 118 files have been seen to comunicate with download.ytddownloader.com in live environments.

 
Latest 20 of 131 files

URL:
http://download.ytddownloader.com/

Google Analytics:
UA-25210420

Title:
“YTD Video Converter”

Web server:
nginx