www.2downloadz.com

Whois Privacy Protection Service, Inc.  (Proxy Registrant)

Domain Information

The domain www.2downloadz.com is registered by proxy through NAME.COM, INC. and was originally registered in February of 2013. Currently this domain has been known to host various forms of malware. The hosted servers are located in Atlanta, Georgia within the United States which resides on the Namecheap, Inc. network.
Registrar:
NAME.COM, INC.

Server location:
Georgia, United States (US)

Create date:
Friday, February 15, 2013

Expires date:
Wednesday, February 15, 2017

Updated date:
Friday, March 04, 2016

ASN:
AS22612 NAMECHEAP-NET - Namecheap, Inc., US

Root domain:

Scanner detections:
Malware distribution  (67% detected)

Scan engine
Details
Detections

avast!
Win32:Malware-gen, Win32:Rootkit-gen [Rtk], Win32:GenMalicious-JNL [Trj]
81.82%

McAfee
Artemis!26FD07A21939, Program.Artemis!81F651BD79F0, Trojan.Artemis!7F4647FDAE81
45.45%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696
45.45%

ESET NOD32
Win32/Packed.Autoit.H suspicious application
45.45%

Emsisoft Anti-Malware
Trojan.Generic.11352583, Trojan.Generic.12427773, Trojan.ScriptKD.555
45.45%

Antiy Labs AVL
Trojan/Win32.FakeAV.gen, Trojan/Win32.Agent
36.36%

Trend Micro House Call
TROJ_GEN.F47V0220, TROJ_GE.337FE20B, TROJ_GE.54D5AFF7, TROJ_SPNR.3AGP14
36.36%

ESET NOD32
Win32/Somoto, Win32/Packed.Autoit
27.27%

Comodo Security
UnclassifiedMalware
27.27%

Jiangmin
Trojan/Reconyc.as
27.27%

Kaspersky
Trojan.MSIL.Zapchast, not-a-virus:HEUR:Downloader.Win32.AutoIt
27.27%

nProtect
Adware/W32.Agent.237016, Trojan.Generic.11352583
18.18%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud), Win32.Troj.Zapchast.cy.(kcloud)
18.18%

Panda Antivirus
PUP/MultiToolbar.A, Trj/CI.A
18.18%

G Data
Win32.Trojan.Agent.E786GE, Trojan.Generic.11352583
18.18%

The domain www.2downloadz.com has been seen to resolve to the following 3 IP addresses.

s198.web-hosting.com
April 20, 2016

hst-3-48-25-185.ist.lt
March 7, 2014

hst-169-48-25-185.ist.lt
December 26, 2013

File downloads found at URLs served by www.2downloadz.com.

1 / 68      (inconclusive)

3 / 68      (inconclusive)

7 / 68      (PUP)

6 / 68      (PUP)

3 / 68      (Malware)
http://www.2downloadz.com/auto_download.php?h=9a5y7zrps4  (myegy.com_internet.download.manager_6.17_build_6_by.maher_downloader.exe)

5 / 68      (PUP)
http://www.2downloadz.com/download.php?id=w84bohjhii0qte4b1zuss4jn0eq5wb&j=2&c=070&dlr  (اختبارات شهرية وفصلية ووظائف منزلية خاصة بالسنة الثالثة ابتدائي في جميع المواد downloader.exe)

26 / 68    (Malware)
http://www.2downloadz.com/download.php?id=3puxdopbgdw1jeyrmtxj4fwpt55kji&j=2&c=316&dlr  (by mayoufi tunisia-sat nitro pro v9.0.3.2 (x86 downloader.exe)

7 / 68      (Malware)

8 / 68      (Malware)
http://www.2downloadz.com/.../get_file.php?id=ac0t5rahe3v&uid=mfvvda2ocl  (adidas cccam.cfg cccam magazine-20_downloader.exe)

0 / 68
http://www.2downloadz.com/download.php?id=viz5kd85z9moty6a8g2s2ahr8ewf7k&j=2&c=665&dlr  (فروض و اختبارات اللغة الفرنسية السنة الخامسة ابتدائي لجميع الفصول collection devoirs et compositions)

17 / 68    (Adware)

The following 2 files have been seen to comunicate with www.2downloadz.com in live environments.

URL:
http://www.2downloadz.com/

Google Analytics:
UA-45612191

Title:
“2Downloadz.com | Convert Your Files Into Cash.”

Description:
“Free and easy file upload. Earn money from uploading and sharing your files”

Web server:
Apache (PHP/5.6.19)

Facebook:
Likes:  1
Shares:  18
Comments:  1

Statistics are for the previous month.