getmdownloader.com

United Privacy Corp

Domain Information

The domain getmdownloader.com registered by United Privacy Corp was initially registered in September of 2014 through REGTIME LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
NAMEPAL.COM #8005

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Saturday, September 27, 2014

Expires date:
Sunday, September 27, 2015

Updated date:
Thursday, October 02, 2014

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Amonetizeltd.AA, PUP.Installer.Amonetizeltd.b, PUP.Installer.Amonetizeltd.Z, PUP.Installer.Amonetizeltd.Y, PUP.Installer.Amonetizeltd.y, PUP.Win.Reputation, PUP.Amonetize.ShetefSolutionsConsulting1998.Bundler (M), PUP.Amonetize.Installer.Meta (M), PUP.Amonetize.Bundler (M), PUP.CJSCInve.Installer (M), Threat.Win.Reputation.IMP
81.82%

Malwarebytes
PUP.Optional.InstallMonetizer, PUP.Optional.Monetizer, PUP.Optional.Amonetize, PUP.Optional.Amonetize.A
63.64%

Trend Micro House Call
TROJ_GEN.F47V1222, TROJ_GEN.F47V1126, TROJ_GEN.F47V1114, TROJ_GEN.F47V1103, TROJ_GEN.R0CBH06LG13, TROJ_GEN.F47V1224, TROJ_GEN.F47V1118, TROJ_GEN.F47V0122
63.64%

ESET NOD32
Win32/Amonetize.AA (variant), Win32/Amonetize (variant), Win32/Amonetize.AD (variant), Win32/Amonetize.AG (variant), Win32/Amonetize.AJ (variant)
60.61%

VIPRE Antivirus
Amonetize, Trojan.Win32.Generic, Threat.4150696
54.55%

McAfee
Artemis!80228DBE0E81, Artemis!F0B991FC49D6, Artemis!618DA847F268, RDN/Generic.hra!bv, Artemis!466A950A6E7B, Artemis!43FAAEE39B14, Artemis!4DF44C13CC80, Adware-Amonetize!150291AC81A4, Adware-Amonetize!D10282E7955B, Adware-Amonetize!A344D0D1EA02, Adware-Amonetize!5E25C1B59026, Adware-Amonetize!75B5F2E2A99A, Adware-Amonetize!D7E90BB18D3F, Artemis!07386133B80B, Adware-Amonetize!B0D8CCD0ACBB, Adware-Amonetize!C061322F7C02
51.52%

Dr.Web
Adware.Downware.1655, Adware.Downware.1528, Adware.Downware.1729, Adware.Downware.1833, Adware.Downware.2083, Adware.Downware.2467
51.52%

McAfee Web Gateway
Artemis!80228DBE0E81, Artemis!F0B991FC49D6, Artemis!618DA847F268, RDN/Generic.hra!bv, Artemis!466A950A6E7B, Artemis!43FAAEE39B14
51.52%

Sophos
Amonetize, Generic PUA DE, PUA 'Amonetize'
45.45%

avast!
Win32:Rootkit-gen [Rtk], Win32:Malware-gen, Win32:Amonetize-E [PUP], Win32:Amonetize-F [PUP], Win32:Adware-BJY [PUP], Win32:Amonetize-AM [PUP], Win32:Amonetize-AK [PUP]
42.42%

Avira AntiVirus
ADWARE/Adware.Gen2, TR/Trash.Gen, PUA/MediaFinder.J
36.36%

AhnLab V3 Security
PUP/Win32.Amonetiz
36.36%

AVG
Generic_r, MalSign.Generic, Generic5, Adware Generic_r.JX
30.30%

Comodo Security
ApplicUnwnt
27.27%

Fortinet FortiGate
Riskware/Amonetize
27.27%

The domain getmdownloader.com has been seen to resolve to the following 6 IP addresses.

July 19, 2016

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
May 15, 2016

December 2, 2014

unallocated.barefruit.co.uk
August 13, 2014

6.54.serverel.net
March 14, 2014

138.255.serverel.net
February 2, 2014

File downloads found at URLs served by getmdownloader.com.

1 / 68      (Adware)

9 / 68      (Adware)
http://getmdownloader.com/download/.../74yVrX95B5iQCnH9TU MXshKJE=&k=IROGWPvsbQi33DkmjsxI-W-5Kk_0BVVHB5cM-jOO68KsjuT0jUvf2m899SlmJBfAkUrDc6eu4Kf6BaGPQyDYZs8  (download.all.in.one.1002b.phpselect.scripts.torrent...kickasstorrents__5547_i422501953_il9760292.exe)

18 / 68    (Adware)
http://getmdownloader.com/download/.../C8uayp3u&k=IVHXnhUpcDQcOOM5WWmj0dEnG3Q26N53DIaLn-O9u9lBfr-tP8MRQuNS55fwGFP_LGI6vsSj2XcuM5pjKp0CdYw  (engineering.mechanics.statics.dynamics.hibbeler.13th.edition.solutions.manual.1.pdf__5547_i380740579)

 
Latest 30 of 100 download URLs

The following 445 files have been seen to comunicate with getmdownloader.com in live environments.

TCP » 54.72.9.51:80

 
Latest 20 of 449 files

URL:
http://getmdownloader.com/

Google Analytics:
UA-48689684

Title:
“getmdownloader.com”

Web server:
nginx

30 of 618 related domains