mymediadownloadsnineteen.com

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain mymediadownloadsnineteen.com is registered by proxy through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM and was originally registered in September of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Austin, Texas within the United States which resides on the YHC Corporation network.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Texas, United States (US)

Create date:
Friday, September 11, 2015

Expires date:
Sunday, September 11, 2016

Updated date:
Friday, September 11, 2015

ASN:
AS40034 CONFLUENCE-NETWORK-INC - Confluence Networks Inc,VG

Scanner detections:
Detections  (82% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Bundler (M)
90.24%

Dr.Web
infected with Trojan.Amonetize.8350, infected with Trojan.Amonetize.10283
7.32%

Emsisoft Anti-Malware
Gen:Application.Imonetize, Application.Bundler.Amonetize.CG
7.32%

ESET NOD32
Win32/Amonetize.II potentially unwanted application, Win32/Amonetize.KA potentially unwanted application
7.32%

Kaspersky
not-a-virus:AdWare.Win32.Amonetize, not-a-virus:Downloader.Win32.Agent
7.32%

Lavasoft Ad-Aware
Gen:Application.Imonetize.2, Application.Bundler.Amonetize.CG
7.32%

McAfee
Program.Artemis!E809DC57A68E
4.88%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A
2.44%

F-Secure
Application:W32/Generic.70053c248f!Online
2.44%

The domain mymediadownloadsnineteen.com has been seen to resolve to the following 2 IP addresses.

209-99-40-223.fwd.datafoundry.com
September 13, 2016

October 1, 2015

File downloads found at URLs served by mymediadownloadsnineteen.com.

 
Latest 30 of 79 download URLs

The following 26 files have been seen to comunicate with mymediadownloadsnineteen.com in live environments.

 
Latest 20 of 30 files

URL:
http://mymediadownloadsnineteen.com/

Title:
“Download Genius — Select the server for direct downloading”

Web server:
nginx/1.0.15