hotspot-shield.joydownload.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain hotspot-shield.joydownload.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Monday, March 18, 2013

Expires date:
Saturday, March 18, 2017

Updated date:
Thursday, January 28, 2016

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

McAfee
Artemis!8E050480D4C6, Artemis!BBF873FB7C7A, Artemis!9640312D2A76, Artemis!6E5335EBFE46, Artemis!5B18EB832632, Artemis!0B7A10D6A9CA
100.00%

Malwarebytes
PUP.Optional.OpenCandy
100.00%

Trend Micro House Call
Suspicious_GEN.F47V0724, Suspici.218D75EB, ADW_OPENCANDY
100.00%

VIPRE Antivirus
Opencandy, Sevas-S Installer
100.00%

AVG
Generic, AdLoad.OpenCandy
100.00%

Reason Heuristics
PUP.InnovativeSystems.W, Threat.Installer.InnovativeSystems, PUP.InnovativeSystems.Installer (M)
100.00%

avast!
Win32:Adware-gen [Adw], Win32:Trojan-gen, Win32:Rootkit-gen [Rtk]
85.71%

Sophos
Generic PUA MC
85.71%

Agnitum Outpost
Riskware.Agent
85.71%

Dr.Web
Adware.Downware.6712, Adware.OpenCandy.47, Adware.OpenCandy.55
85.71%

Avira AntiVirus
APPL/Downloader.Gen
85.71%

G Data
Win32.Adware.OpenCandy, Win32.Trojan.Agent.DO7U7A
85.71%

AhnLab V3 Security
PUP/Win32.OpenCandy
85.71%

Baidu Antivirus
Adware.Win32.JoyDownloader, Adware.Win32.OpenCandy
85.71%

ESET NOD32
Win32/JoyDownloader
71.43%

The domain hotspot-shield.joydownload.com has been seen to resolve to the following 4 IP addresses.

ec2-50-19-96-56.compute-1.amazonaws.com
February 27, 2016

ec2-54-225-168-223.compute-1.amazonaws.com
February 27, 2016

ec2-107-22-195-231.compute-1.amazonaws.com
August 12, 2014

ec2-23-23-108-120.compute-1.amazonaws.com
August 12, 2014

File downloads found at URLs served by hotspot-shield.joydownload.com.

URL:
http://hotspot-shield.joydownload.com/

Title:
“Hotspot shield 3.42 download. Free download hotspot shield 3.42 for windows - JoyDownload”

Description:
“Hotspot Shield is a powerful free application which provides security in public Wi-Fi connections - Download Hotspot Shield latest version here.”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx/1.9.12 (PHP/5.3.10-1ubuntu3.21)

Facebook:
Likes:  84
Shares:  396
Comments:  25

Statistics are for the previous month.