internet-download.joydownload.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain internet-download.joydownload.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Monday, March 18, 2013

Expires date:
Saturday, March 18, 2017

Updated date:
Thursday, January 28, 2016

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (93% detected)

Scan engine
Details
Detections

AVG
Generic, Adware AdLoad.OpenCandy, Win32/Virut, Win32/Sality
100.00%

Dr.Web
Adware.OpenCandy.10, Adware.Downware.6712, Adware.OpenCandy.55, Win32.Virut.56, Win32.Sector.30
92.86%

McAfee
Adware-OpenCandy.a, Artemis!BBE4BD3BF287, Artemis!215A44EF4A15, Artemis!531D64878C22, Artemis!045AAB13437B, Artemis!2A2CC871B2C2, Artemis!CA1C5128524B, Virus.W32/Chir.gen!remnants
85.71%

Reason Heuristics
PUP.InnovativeSystems.I, PUP.InnovativeSystems.O, PUP.InnovativeSystems.P, PUP.RICHMEDIASYSTEMS.Installer (M), PUP.Innovati.Installer (M)
85.71%

Malwarebytes
PUP.Optional.OpenCandy
71.43%

Agnitum Outpost
Riskware.OpenCandy, Riskware.Agent
71.43%

Sophos
OpenCandy, Generic PUA LG, Virus 'W32/Scribble-B'
71.43%

Baidu Antivirus
Adware.Win32.Agent, Adware.Win32.OpenCandy, Adware.Win32.JoyDownloader
71.43%

Trend Micro House Call
Suspici.F184F561, Suspicious_GEN.F47V0729, Suspici.218D75EB, Suspici.792C221A, Suspicious_GEN.F47V1114, ADW_OPENCANDY
64.29%

VIPRE Antivirus
Opencandy, Threat.4150696, Sevas-S Installer, Trojan.Win32.Generic, Threat.4120919
64.29%

ESET NOD32
Win32/JoyDownloader
64.29%

K7 AntiVirus
Unwanted-Program , Trojan
64.29%

Avira AntiVirus
APPL/Downloader.Gen
64.29%

G Data
Win32.Trojan.Agent.Y4VLYP, Win32.Adware.OpenCandy
57.14%

avast!
Win32:Adware-gen [Adw], Rootkit-gen [Rtk], Win32:Rootkit-gen [Rtk], Win32:Vitro, Win32:SaliCode
42.86%

The domain internet-download.joydownload.com has been seen to resolve to the following 9 IP addresses.

ec2-54-225-168-223.compute-1.amazonaws.com
February 1, 2016

ec2-50-19-96-56.compute-1.amazonaws.com
February 1, 2016

ec2-54-235-130-12.compute-1.amazonaws.com
July 1, 2015

ec2-23-21-241-197.compute-1.amazonaws.com
December 2, 2014

ec2-23-23-159-111.compute-1.amazonaws.com
December 2, 2014

ec2-107-22-254-230.compute-1.amazonaws.com
September 18, 2014

ec2-184-73-244-120.compute-1.amazonaws.com
September 18, 2014

ec2-23-23-108-120.compute-1.amazonaws.com
August 10, 2014

ec2-107-22-195-231.compute-1.amazonaws.com
August 10, 2014

File downloads found at URLs served by internet-download.joydownload.com.

 
Latest 30 of 74 download URLs

The following file have been seen to comunicate with internet-download.joydownload.com in live environments.

URL:
http://internet-download.joydownload.com/

Title:
“Internet Download Manager 6.21. Free download IDM 6.21 for windows - JoyDownload”

Description:
“Internet Download Manager (IDM) – mutlifunctional file transfer/download manager that can accelerate your download speed significantly - Download Internet Download Manager latest version here.”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx/1.9.12 (PHP/5.3.10-1ubuntu3.21)

Facebook:
Likes:  135
Shares:  388
Comments:  24

Statistics are for the previous month.