safe.download.downloadastro.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain safe.download.downloadastro.com is registered by proxy through GODADDY.COM, LLC and was originally registered in August of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Remove Malware from safe.download.downloadastro.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Oregon, United States (US)

Create date:
Wednesday, August 08, 2012

Expires date:
Sunday, August 08, 2021

Updated date:
Tuesday, May 12, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.installCore.WEBCELLENCE, PUP.Webcellence, PUP.Installer.SymbolicomHoldings, Threat.Installer.SymbolicomHoldings, PUP.Bundler.SymbolicomHoldings, PUP.Installer.Webcellence, PUP.SymbolicomHoldings.Installer (M), PUP.installCore.WEBCELLENCE (M), PUP.installCore.Webcellence (M), PUP.installCore.SymbolicomHoldings (M), PUP.installCore.SymbolicomHoldings.Installer (M), PUP.InstallCore.AmirRaismanLawyer.Installer (M)
95.74%

AVG
Generic
40.43%

VIPRE Antivirus
Threat.4150696, Threat.5063361, Trojan.Win32.Generic
36.17%

Dr.Web
Trojan.InstallCore.7, Trojan.Packed.24524, Trojan.InstallCore.10, Trojan.MulDrop5.38502, Trojan.MulDrop5.38104, Trojan.InstallCore.1408
36.17%

ESET NOD32
Win32/InstallCore.QW potentially unwanted application, Win32/InstallCore.QD potentially unwanted application, Win32/InstallCore.VW potentially unwanted application
31.91%

Avira AntiVirus
ADWARE/InstallCore.Gen, ADWARE/InstallCore.Gen7, PUA/InstallCore.Gen, PUA/InstallCore.Gen7
31.91%

K7 AntiVirus
Trojan , Unwanted-Program
29.79%

K7 Gateway Antivirus
Trojan , Unwanted-Program
29.79%

NANO AntiVirus
Riskware.Win32.InstallCore.dmkftg, Riskware.Win32.InstallCore.dmfojl, Riskware.Win32.InstallCore.dcnbqn, Riskware.Win32.InstallCore.djeefp
27.66%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen, Downware.InstallCore, SScope.Malware-Cryptor.InstallCore
27.66%

Agnitum Outpost
PUA.InstallCore
23.40%

herdProtect (fuzzy)
a variant of 6038917881106e981ef2fd22629c840a47b0ae62, a variant of a9a9630ff46c72510ce915be0b2bf389abc3b0d3, a variant of 8c62a888e40c13a3f972b4e31d1fd55bd7fedc7d
21.28%

Sophos
PUA 'Install Core Click run software', Generic PUA NG
17.02%

Bkav FE
W32.HfsAdware
14.89%

ESET NOD32
Win32/InstallCore.QC (variant), Win32/InstallCore.QW potentially unwanted (variant), Win32/InstallCore.PQ (variant)
12.77%

The domain safe.download.downloadastro.com has been seen to resolve to the following 35 IP addresses.

ec2-54-69-11-66.us-west-2.compute.amazonaws.com
January 28, 2016

ec2-52-88-159-85.us-west-2.compute.amazonaws.com
January 28, 2016

ec2-52-35-10-15.us-west-2.compute.amazonaws.com
January 28, 2016

ec2-52-34-170-106.us-west-2.compute.amazonaws.com
December 16, 2015

ec2-52-25-23-136.us-west-2.compute.amazonaws.com
December 16, 2015

ec2-54-191-37-5.us-west-2.compute.amazonaws.com
December 16, 2015

ec2-54-148-75-228.us-west-2.compute.amazonaws.com
October 26, 2015

ec2-52-24-62-64.us-west-2.compute.amazonaws.com
October 26, 2015

ec2-54-149-60-150.us-west-2.compute.amazonaws.com
October 26, 2015

ec2-52-10-176-223.us-west-2.compute.amazonaws.com
October 12, 2015

ec2-54-191-250-3.us-west-2.compute.amazonaws.com
October 7, 2015

ec2-52-26-172-249.us-west-2.compute.amazonaws.com
August 13, 2015

ec2-54-201-218-17.us-west-2.compute.amazonaws.com
June 19, 2015

ec2-52-25-88-134.us-west-2.compute.amazonaws.com
June 18, 2015

ec2-54-186-33-198.us-west-2.compute.amazonaws.com
May 28, 2015

ec2-54-154-127-102.eu-west-1.compute.amazonaws.com
May 28, 2015

ec2-52-10-0-96.us-west-2.compute.amazonaws.com
May 5, 2015

ec2-54-187-120-35.us-west-2.compute.amazonaws.com
November 29, 2014

ec2-54-68-221-84.us-west-2.compute.amazonaws.com
November 18, 2014

ec2-54-186-167-43.us-west-2.compute.amazonaws.com
November 17, 2014

ec2-54-191-192-141.us-west-2.compute.amazonaws.com
September 27, 2014

ec2-54-68-210-152.us-west-2.compute.amazonaws.com
September 22, 2014

ec2-54-68-212-83.us-west-2.compute.amazonaws.com
September 22, 2014

ec2-54-186-219-20.us-west-2.compute.amazonaws.com
September 1, 2014

ec2-54-213-239-193.us-west-2.compute.amazonaws.com
August 26, 2014

ec2-54-200-190-106.us-west-2.compute.amazonaws.com
August 26, 2014

ec2-54-201-96-17.us-west-2.compute.amazonaws.com
August 7, 2014

ec2-54-187-25-184.us-west-2.compute.amazonaws.com
July 23, 2014

ec2-54-191-124-126.us-west-2.compute.amazonaws.com
July 10, 2014

ec2-54-201-87-165.us-west-2.compute.amazonaws.com
July 7, 2014

 
Showing 30 of 35 IP Addresses

File downloads found at URLs served by safe.download.downloadastro.com.

1 / 68      (Adware)

The following file have been seen to comunicate with safe.download.downloadastro.com in live environments.

Remove Malware from safe.download.downloadastro.com - Powered by Reason Core Security