es.joydownload.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain es.joydownload.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Remove Malware from es.joydownload.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Monday, March 18, 2013

Expires date:
Saturday, March 18, 2017

Updated date:
Thursday, January 28, 2016

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (97% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SevasS.M, PUP.SevasS.R, PUP.SevasS.S, PUP.SevasS.N, PUP.SevasS.O, PUP.SevasS.E, PUP.SevasS.?, PUP.SevasS.H, PUP.SevasS.l, PUP.SevasS.Installer (M)
97.22%

Malwarebytes
PUP.Optional.OpenCandy
94.44%

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
94.44%

Dr.Web
Adware.Downware.1446, Adware.Downware.3115
91.67%

ESET NOD32
Win32/JoyDownloader, Win32/OpenCandy
91.67%

McAfee
Artemis!B79AA28E92EB, Artemis!05ABA008CD79, Artemis!DEF32AE932B4, Artemis!130EEDA1E119, Artemis!588B4375786A, Artemis!DA4D69460BBE, Artemis!9F105F06F980, Artemis!E99A45E380E6, Artemis!4FA9BA13C807, Artemis!B1CDEBDD89A1, Artemis!1463B3BF03CC, Artemis!954C0E94B27C, Artemis!3D3B1AD5C132, Artemis!0DC4B7E7ED1C, Artemis!F873A2B527C6, Artemis!9A3E4133BED1, Artemis!AAA6687E035B, Artemis!6785C817FE00, Artemis!4EC8D9492749, Artemis!B1F998C852D8, Artemis!AD3734C560C4, Artemis!EC0A73AF6A0D, Artemis!637E8073E169, Artemis!485F62836966, Artemis!EC3AB68A74FF
80.56%

McAfee Web Gateway
Artemis!B79AA28E92EB, Artemis!05ABA008CD79, Artemis!DEF32AE932B4, Artemis!130EEDA1E119, Artemis!588B4375786A, Artemis!DA4D69460BBE
80.56%

AVG
Downloader, Sevas, OpenCandy
77.78%

VIPRE Antivirus
Sevas-S Installer
77.78%

Trend Micro House Call
TROJ_GEN.F47V1214, ADW_OPENCANDY, TROJ_GEN.F47V1126, TROJ_GEN.F47V0318, TROJ_GEN.F47V0416, TROJ_GEN.F47V0418, TROJ_GEN.F47V0417
66.67%

Agnitum Outpost
Riskware.OpenCandy
55.56%

Sophos
Generic PUA EN, Generic PUA KN, Generic PUA IN, Generic PUA HL, Generic PUA IF, Generic PUA KF, OpenCandy, Generic PUA DJ
50.00%

K7 AntiVirus
Unwanted-Program
44.44%

Trend Micro
ADW_OPENCANDY
36.11%

K7 Gateway Antivirus
Unwanted-Program
33.33%

The domain es.joydownload.com has been seen to resolve to the following 15 IP addresses.

ec2-50-19-96-56.compute-1.amazonaws.com
January 29, 2016

ec2-54-225-168-223.compute-1.amazonaws.com
January 29, 2016

ec2-174-129-255-54.compute-1.amazonaws.com
November 7, 2015

ec2-107-21-96-117.compute-1.amazonaws.com
November 7, 2015

ec2-54-235-115-186.compute-1.amazonaws.com
October 1, 2015

ec2-54-243-117-101.compute-1.amazonaws.com
October 1, 2015

ec2-54-235-130-12.compute-1.amazonaws.com
July 1, 2015

ec2-23-21-241-197.compute-1.amazonaws.com
December 1, 2014

ec2-23-23-159-111.compute-1.amazonaws.com
December 1, 2014

ec2-23-23-108-120.compute-1.amazonaws.com
August 28, 2014

ec2-107-22-195-231.compute-1.amazonaws.com
August 28, 2014

ec2-23-23-156-132.compute-1.amazonaws.com
May 10, 2014

ec2-54-235-94-58.compute-1.amazonaws.com
April 25, 2014

ec2-50-19-116-81.compute-1.amazonaws.com
March 28, 2014

ec2-23-23-158-167.compute-1.amazonaws.com
February 15, 2014

File downloads found at URLs served by es.joydownload.com.

14 / 68    (Adware)

18 / 68    (Adware)
http://es.joydownload.com/wi/1/3/1/.../virtualdj-7.4.exe  (ec3ab68a74ffda5bfce57e7b43c2dc4d)

12 / 68    (Adware)

1 / 68      (inconclusive)

15 / 68    (Adware)

1 / 68      (inconclusive)

14 / 68    (Adware)

15 / 68    (Adware)

9 / 68      (Adware)

9 / 68      (Adware)

9 / 68      (Adware)

15 / 68    (Adware)

14 / 68    (Adware)

20 / 68    (Adware)

15 / 68    (Adware)

 
Latest 30 of 54 download URLs

The following file have been seen to comunicate with es.joydownload.com in live environments.

URL:
http://es.joydownload.com/

Title:
“Descargas gratuitas de software en Windows - JoyDownload”

Description:
“Colección de programas gratuitas y versiones de prueba para descargar.”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx/1.7.6 (PHP/5.3.10-1ubuntu3.8)

Facebook:
Likes:  2
Shares:  26

Statistics are for the previous month.

Remove Malware from es.joydownload.com - Powered by Reason Core Security