link.pcspeedup.com

Safe Download Ltd

Domain Information

The domain link.pcspeedup.com registered by Safe Download Ltd was initially registered in September of 2002 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Remove Malware from link.pcspeedup.com - Powered by Reason Core Security
Registrar:
GANDI SAS

Server location:
Virginia, United States (US)

Create date:
Monday, September 16, 2002

Expires date:
Friday, September 16, 2016

Updated date:
Tuesday, November 11, 2014

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.SafeDownloadLimited.K, PUP.Optional.SafeDownloadLimited.n, PUP.SafeDownloadLimited.r, PUP.OptimalSoftwaresro.l, PUP.OptimalSoftwaresro.W
100.00%

ESET NOD32
Win32/Speedchecker (variant)
89.47%

Dr.Web
Program.Unwanted.12, riskware program Program.Unwanted.12, BackDoor.Infector.133, Win32.Sector.30
73.68%

NANO AntiVirus
Riskware.Win32.Agent.dagvik, Riskware.Win32.Unwanted.deqwxg
63.16%

Trend Micro House Call
TROJ_GEN.F47V0509, Suspicious_GEN.F47V0716, Suspicious_GEN.F47V0729, Suspicious_GEN.F47V1127, Suspicious_GEN.F47V1211, Suspicious_GEN.F47V1126, Suspicious_GEN.F47V0120
42.11%

McAfee
Artemis!A5B1D9F6A779, Artemis!D2175A586554, Artemis!D80E80E3AB32, Artemis!63A3382AE47B, Artemis!940B98FE6726, Virus.W32/Sality.gen.z
31.58%

McAfee Web Gateway
Artemis!A5B1D9F6A779, Artemis!D2175A586554
31.58%

IKARUS anti.virus
PUA.Speedchecker
21.05%

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
10.53%

ESET NOD32
Win32/Speedchecker.A potentially unwanted application, Win32/Sality.NBA virus
10.53%

AVG
Optimal Software s.r.o., Win32/Sality
10.53%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
5.26%

herdProtect (fuzzy)
a variant of 499691d001c2962eed1408e64a36b005b3df02b7
5.26%

Fortinet FortiGate
Riskware/Speedchecker
5.26%

Norman
Win32.Sality.3
5.26%

The domain link.pcspeedup.com has been seen to resolve to the following 18 IP addresses.

ec2-54-173-193-7.compute-1.amazonaws.com
June 18, 2015

ec2-54-86-172-158.compute-1.amazonaws.com
June 18, 2015

ec2-107-23-100-205.compute-1.amazonaws.com
June 18, 2015

ec2-54-175-84-195.compute-1.amazonaws.com
May 2, 2015

ec2-54-175-1-157.compute-1.amazonaws.com
May 2, 2015

ec2-54-173-20-116.compute-1.amazonaws.com
May 2, 2015

ec2-54-236-179-48.compute-1.amazonaws.com
November 29, 2014

ec2-54-173-236-230.compute-1.amazonaws.com
November 29, 2014

ec2-54-236-216-239.compute-1.amazonaws.com
November 29, 2014

ec2-54-183-42-248.us-west-1.compute.amazonaws.com
September 5, 2014

ec2-50-18-209-44.us-west-1.compute.amazonaws.com
August 12, 2014

ec2-107-23-165-131.compute-1.amazonaws.com
May 1, 2014

ec2-107-23-142-44.compute-1.amazonaws.com
May 1, 2014

ec2-107-21-52-90.compute-1.amazonaws.com
May 1, 2014

ec2-54-246-131-227.eu-west-1.compute.amazonaws.com
April 14, 2014

ec2-54-229-12-122.eu-west-1.compute.amazonaws.com
April 14, 2014

ec2-54-246-131-211.eu-west-1.compute.amazonaws.com
March 14, 2014

ec2-50-18-211-52.us-west-1.compute.amazonaws.com
February 5, 2014

File downloads found at URLs served by link.pcspeedup.com.

5 / 68      (PUP)

7 / 68      (PUP)

7 / 68      (PUP)

4 / 68      (PUP)
http://link.pcspeedup.com/aff_c?offer_id=5&aff_id=1&source=usbcachefree&url_id=45  (pcspeedupru_f6a13965b642415194d9926130e45a71_.exe)

The following 6 files have been seen to comunicate with link.pcspeedup.com in live environments.

URL:
http://link.pcspeedup.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx/1.7.9

Remove Malware from link.pcspeedup.com - Powered by Reason Core Security