es.joydownload.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain es.joydownload.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Monday, March 18, 2013

Expires date:
Saturday, March 18, 2017

Updated date:
Thursday, January 28, 2016

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc., US

Root domain:

Scanner detections:
Detections  (85% detected)

Scan engine
Details
Detections

Reason Heuristics
(M), PUP.SevasS.R, PUP.SevasS.X, PUP.SevasS.H, PUP.SevasS.N, PUP.SevasS.O, PUP.SevasS.f, PUP.SevasS.Q, PUP.SevasS.S, PUP.SevasS.?, PUP.SevasS.Installer (M), PUP.SaveAs.Installer (M)
97.14%

Malwarebytes
PUP.Optional.OpenCandy
80.00%

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
80.00%

ESET NOD32
Win32/JoyDownloader, Win32/OpenCandy, Win32/JoyDownloader.D potentially unwanted
77.14%

Dr.Web
Adware.Downware.1446, Adware.Downware.3115
74.29%

VIPRE Antivirus
Sevas-S Installer
74.29%

McAfee
Artemis!DEF32AE932B4, Artemis!C98D17D97676, Artemis!588B4375786A, Artemis!DA4D69460BBE, Artemis!A32DA0691E74, Artemis!D82DD19BA09F, Artemis!477A52207229, Artemis!954C0E94B27C, Artemis!EE33A3A442F8, Artemis!904409F18824, Artemis!3F06D0F6ECFA, Artemis!AAA6687E035B, Artemis!6785C817FE00, Artemis!CCE2F8AA17C0, Artemis!EA524D4AE6FB, Artemis!A1DE35B63873, Artemis!18F45E2F8DC1, Artemis!C2D0ECEB2356, Artemis!0E344E147A72, Artemis!96511DAE4736
71.43%

McAfee Web Gateway
Artemis!DEF32AE932B4, Artemis!C98D17D97676, Artemis!588B4375786A, Artemis!DA4D69460BBE, Artemis!A32DA0691E74, Artemis!D82DD19BA09F
71.43%

AVG
Downloader, Skodna.Generic_c, MalSign.Sevas, OpenCandy
71.43%

Trend Micro House Call
TROJ_GEN.F47V1126, ADW_OPENCANDY, TROJ_GEN.F47V0208, TROJ_GEN.F47V0318, TROJ_GEN.F47V1214, TROJ_GEN.R0CBH06BS14, TROJ_GEN.F47V0416
51.43%

Agnitum Outpost
Riskware.OpenCandy
51.43%

Sophos
Generic PUA EN, Generic PUA IO, Generic PUA EB, Generic PUA KN, Generic PUA IF, OpenCandy, Generic PUA BH
42.86%

K7 AntiVirus
Unwanted-Program
40.00%

K7 Gateway Antivirus
Unwanted-Program , Trojan
34.29%

Avira AntiVirus
W32/Mabezat, APPL/Sevas.M, APPL/Sevas.K, APPL/Sevas.Q, Adware/OpenCandy.486864, Adware/JoyDownloader.A.1, APPL/Downloader.Gen
31.43%

The domain es.joydownload.com has been seen to resolve to the following 19 IP addresses.

ec2-184-73-214-48.compute-1.amazonaws.com
September 16, 2016

ec2-54-243-203-164.compute-1.amazonaws.com
September 16, 2016

ec2-204-236-230-156.compute-1.amazonaws.com
February 28, 2016

ec2-54-204-41-226.compute-1.amazonaws.com
February 28, 2016

ec2-50-19-96-56.compute-1.amazonaws.com
January 29, 2016

ec2-54-225-168-223.compute-1.amazonaws.com
January 29, 2016

ec2-174-129-255-54.compute-1.amazonaws.com
November 7, 2015

ec2-107-21-96-117.compute-1.amazonaws.com
November 7, 2015

ec2-54-235-115-186.compute-1.amazonaws.com
October 1, 2015

ec2-54-243-117-101.compute-1.amazonaws.com
October 1, 2015

ec2-54-235-130-12.compute-1.amazonaws.com
July 1, 2015

ec2-23-21-241-197.compute-1.amazonaws.com
December 1, 2014

ec2-23-23-159-111.compute-1.amazonaws.com
December 1, 2014

ec2-23-23-108-120.compute-1.amazonaws.com
August 28, 2014

ec2-107-22-195-231.compute-1.amazonaws.com
August 28, 2014

ec2-23-23-156-132.compute-1.amazonaws.com
May 10, 2014

ec2-54-235-94-58.compute-1.amazonaws.com
April 25, 2014

ec2-50-19-116-81.compute-1.amazonaws.com
March 28, 2014

ec2-23-23-158-167.compute-1.amazonaws.com
February 15, 2014

File downloads found at URLs served by es.joydownload.com.

16 / 68    (Adware)

1 / 68      (Adware)

11 / 68    (Adware)

15 / 68    (Adware)

18 / 68    (Adware)

14 / 68    (Adware)

1 / 68      (Adware)

9 / 68      (Adware)

1 / 68      (Adware)

 
Latest 30 of 176 download URLs

The following file have been seen to comunicate with es.joydownload.com in live environments.

URL:
http://es.joydownload.com/

Title:
“Descargas gratuitas de software en Windows - JoyDownload”

Description:
“Colección de programas gratuitas y versiones de prueba para descargar.”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx/1.9.12 (PHP/5.3.10-1ubuntu3.21)

Facebook:
Likes:  2
Shares:  26

Statistics are for the previous month.