downloadlink.onhax.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain downloadlink.onhax.net is registered by proxy through GODADDY.COM, LLC and was originally registered in April of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Digital Ocean, Inc. network.
Remove Malware from downloadlink.onhax.net - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
New York, United States (US)

Create date:
Monday, April 22, 2013

Expires date:
Friday, April 22, 2016

Updated date:
Friday, May 01, 2015

Root domain:

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.InstallMonetizer, PUP.Optional.Amonetize, PUP.Optional.Amonetize.A, PUP.Optional.OffersWizard.A, PUP.Optional.Multiplug
83.67%

AhnLab V3 Security
PUP/Win32.Amonetiz, PUP/Win32.Amonetize, PUP/Win32.MultiPlug, Trojan/Win32.Downloader, PUP/Win32.Generic
83.67%

McAfee
Adware-Amonetize!9468B3566BA3, Artemis!08F28581B55F, Artemis!3C84784ECC02, Artemis!C8C26D142DF0, Artemis!C0CBD31E9FCC, Artemis!DBB0C1568950, Artemis!31EAC5D0E8D7, Artemis!AAD320A99B7B, Artemis!5E4535A1F390, Artemis!B1D27C763978, Artemis!D398895D0274, PUP-FBM!C9F53E3EC388, Artemis!2D88D1CE03A3, PUP-FBM!45BDC09BC30C, PUP-FBM!DE032207FCDD, Artemis!B46BAF9148A5, Artemis!2C04316F09EC, Artemis!CDC63E319936
81.63%

avast!
Win32:Amonetize-E [PUP], Win32:Amonetize-F [PUP], Win32:Amonetize-N [PUP], Win32:Amonetize-S [PUP], Win32:Amonetize-Y [PUP], Win32:Amonetize-BJ [PUP]
79.59%

McAfee Web Gateway
Adware-Amonetize!9468B3566BA3, Artemis!08F28581B55F, Artemis!3C84784ECC02, Artemis!C8C26D142DF0, Artemis!C0CBD31E9FCC, Artemis!DBB0C1568950
79.59%

Avira AntiVirus
ADWARE/Adware.Gen2, Adware/Graftor.146078.139, TR/Crypt.ZPACK.Gen8, APPL/Amonetize.htzw, TR/Crypt.XPACK.Gen, Adware/MultiPlug.bfp
77.55%

Sophos
Amonetize, Generic PUA NH, Generic PUA DD, Mal/Generic-S, Generic PUA AM, Generic PUA HN, MultiPlug, PUA 'MultiPlug' (of type Adware)
73.47%

ESET NOD32
Win32/Amonetize.AD (variant), Win32/Amonetize.AI (variant), Win32/Amonetize.AJ (variant), Win32/Amonetize.AO (variant), Win32/Amonetize.AS (variant)
73.47%

Reason Heuristics
PUP.Installer.Amonetizeltd.GG, PUP.Installer.ShetefSolutionsConsulting1998.d, PUP.Wilmaonline.?, PUP.Wilmaonline., PUP.Wilmaonline.AA, PUP.Installer.KOMPANIYAR.AA, PUP.Installer.KOMPANIYAR.g, PUP.Installer.Wilmaonline.BB, PUP.Installer.OlehAleksyuk.P, Threat.Installer.OlehAleksyuk
73.47%

Dr.Web
Adware.Downware.1833, Adware.Downware.1575, Adware.Downware.2250, Adware.Downware.2467, Adware.Downware.3925, Adware.Downware.5546
71.43%

AVG
MalSign.Wilmo, Generic_r, BundleApp_r.R, Adware Generic5.BIVI, Adware Generic5.BLIM, Adware Generic5.BLIG, Adware Generic_r.VD
69.39%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize, not-a-virus:AdWare.Win32.Amonetize, not-a-virus:AdWare.Win32.MultiPlug
59.18%

G Data
Trojan.GenericKD.1621722, Trojan.GenericKD.1613781, Trojan.GenericKD.1688970, Gen:Variant.Application.Bundler.Amonetize
51.02%

Baidu Antivirus
Adware.Win32.Amonetize, Adware.Win32.MultiPlug
46.94%

Bitdefender
Trojan.GenericKD.1621722, Trojan.GenericKD.1613781, Trojan.GenericKD.1688970, Gen:Variant.Application.Bundler.Amonetize.8
42.86%

The domain downloadlink.onhax.net has been seen to resolve to the following 10 IP addresses.

149.126.72.114.ip.incapdns.net
September 4, 2014

149.126.74.70.ip.incapdns.net
September 4, 2014

September 3, 2014

July 23, 2014

July 23, 2014

(CloudFlare)
June 21, 2014

(CloudFlare)
June 21, 2014

onhax.net
April 14, 2014

March 14, 2014

onhax.net
January 19, 2014

File downloads found at URLs served by downloadlink.onhax.net.

32 / 68    (Adware)
http://downloadlink.onhax.net/  (Crack and Setup.exe)

URL:
http://downloadlink.onhax.net/

SSL certificate subject:
CN=sni10796.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
openresty

Remove Malware from downloadlink.onhax.net - Powered by Reason Core Security