download2.manycam.com

Visicom Media Inc.

Domain Information

The domain download2.manycam.com registered by Visicom Media Inc. was initially registered in March of 2006 through DNC HOLDINGS, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Seattle, Washington within the United States. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Remove Malware from download2.manycam.com - Powered by Reason Core Security
Registrar:
DNC HOLDINGS, INC.

Server location:
Washington, United States (US)

Create date:
Wednesday, March 22, 2006

Expires date:
Monday, March 22, 2021

Updated date:
Wednesday, November 20, 2013

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (67% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ManyCamVirtualWebcam.VisicomMedia.M, PUP.ManyCamVirtualWebcam.VisicomMedia.Z, PUP.ManyCamVirtualWebcam.VisicomMedia.W, Threat.Win.Reputation.IMP, PUP.Installer.Visicom, Win32.Generic
57.89%

Rising Antivirus
PE:PUA.Infector!1.9C44, NS:Malware.Install!1.9F62, PE:Malware.XPACK/RDM!5.1
47.37%

ESET NOD32
Win32/Toolbar.Visicom (variant), Win32/Bundled.Toolbar.Ask (variant)
36.84%

Antiy Labs AVL
RemoteAdmin/Win32.RMS.gen, Trojan[RemoteAdmin:not-a-virus]/Win32.RMS
36.84%

Trend Micro House Call
TROJ_GEN.F47V1023, TROJ_GEN.F47V0203, TROJ_GEN.F47V0305
36.84%

Dr.Web
Tool.InstallToolbar.129, Tool.InstallToolbar.174, hacktool program Tool.InstallToolbar.189
26.32%

Malwarebytes
PUP.Optional.MyStartTB.A
15.79%

Agnitum Outpost
PUA.Toolbar.Ask, Riskware.InstallToolbar
15.79%

Emsisoft Anti-Malware
Win32.Parite
15.79%

Vba32 AntiVirus
TrojanDownloader.Genome
15.79%

IKARUS anti.virus
Trojan-PSW.Win32.Minari
5.26%

Bkav FE
W32.HfsAdware
5.26%

AVG
Generic
5.26%

McAfee Web Gateway
BehavesLike.Win32.Backdoor.dh
5.26%

The domain download2.manycam.com has been seen to resolve to the following 14 IP addresses.

server-54-230-193-149.iad53.r.cloudfront.net
February 1, 2016

server-54-230-193-144.iad53.r.cloudfront.net
February 1, 2016

server-54-230-193-130.iad53.r.cloudfront.net
February 1, 2016

server-54-230-193-93.iad53.r.cloudfront.net
February 1, 2016

server-54-230-193-69.iad53.r.cloudfront.net
February 1, 2016

server-54-230-193-253.iad53.r.cloudfront.net
February 1, 2016

server-54-230-193-251.iad53.r.cloudfront.net
February 1, 2016

server-54-230-193-199.iad53.r.cloudfront.net
February 1, 2016

8-127-232-198.static.unitasglobal.net
May 3, 2015

ec2-54-85-181-89.compute-1.amazonaws.com
September 7, 2014

ec2-107-23-237-203.compute-1.amazonaws.com
September 3, 2014

ec2-54-236-128-234.compute-1.amazonaws.com
August 12, 2014

174.127.64.204.static.midphase.com
February 3, 2014

174.127.64.216.static.midphase.com
February 3, 2014

File downloads found at URLs served by download2.manycam.com.

1 / 68      (Adware)
http://download2.manycam.com/ManyCamSetup.exe  (57bfc3611ef888bdb4a8cd991040764a)

3 / 68      (Malware)
http://download2.manycam.com/.../ManyCamWebInstaller.exe  (7edd57ca5a33fa1fbdfdadc9bf2752ec)

1 / 68      (Adware)

5 / 68      (PUP)

1 / 68      (Adware)
http://download2.manycam.com/ManyCamSetup.exe  (535726a40bc7d8a3dfdfee66617677f5)

3 / 68      (inconclusive)

1 / 68

1 / 68      (PUP)

0 / 68
http://download2.manycam.com/ManyCam.exe  (manycamwebinstaller.exe)

2 / 68      (inconclusive)
http://download2.manycam.com/ManyCamSetup.exe  (a76aa1731ec003cfc3ef5a2ca7000c43)

1 / 68      (PUP)
http://download2.manycam.com/ManyCamStandaloneSetup.exe  (45d637a76e5137f9dc4732b171156b22)

7 / 68      (PUP)
http://download2.manycam.com/ManyCamSetup.exe  (cce0fb46a098369d405451ca60dadac6)

3 / 68      (PUP)
http://download2.manycam.com/ManyCamStandaloneSetup.exe  (d51730ff923e6782d544ac5d4295de78)

7 / 68      (PUP)
http://download2.manycam.com/ManyCamSetup.exe  (ac5402519b10f9fcf229e95d1f1facdb)

5 / 68      (PUP)
http://download2.manycam.com/ManyCamSetup.exe  (d3cc2bfb6e02629681bc15c3088e293c)

4 / 68      (PUP)
http://download2.manycam.com/ManyCamSetup.exe  (f8dc2f4ee27af8fea0103bed733af2eb)

4 / 68      (PUP)
http://download2.manycam.com/ManyCamSetup.exe  (34768c3aa9da188ad5d05830d1ad95c1)

3 / 68      (inconclusive)
http://download2.manycam.com/ManyCamSetup.exe  (c471681a3dc68fd027ccba47dfe8800d)

5 / 68      (PUP)

8 / 68      (PUP)

0 / 68
http://download2.manycam.com/ManyCam.exe  (a97be9e75fc7de968f6c548e0cb71a3a)

2 / 68      (inconclusive)
http://download2.manycam.com/ManyCamSetup.exe  (d68a12572283657d63889bc49522551e)

The following 2 files have been seen to comunicate with download2.manycam.com in live environments.

URL:
http://download2.manycam.com/

Network:
Amazon Cloudfront

SSL certificate subject:
CN=*.manycam.com, OU=Domain Control Validated - RapidSSL(R), OU=See www.rapidssl.com/resources/cps (c)15, OU=GT36371141

SSL certificate issuer:
CN=RapidSSL SHA256 CA - G3, O=GeoTrust Inc., C=US

Web server:
cloudflare-nginx

Compete.com:
US visitors:  34

Statistics are for the previous month.

Remove Malware from download2.manycam.com - Powered by Reason Core Security