www.essentialdownload.com

BuyDomains.com

Domain Information

The domain www.essentialdownload.com registered by BuyDomains.com was initially registered in May of 2015 through Moniker Online Services. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
ANNULET LLC

Server location:
Arizona, United States (US)

Create date:
Saturday, May 02, 2015

Expires date:
Tuesday, May 02, 2017

Updated date:
Friday, December 11, 2015

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.Amonetize.A
100.00%

avast!
Win32:Amonetize-AK [PUP], Win32:Amonetize-AM [PUP], Win32:Amonetize-AO [PUP], Win32:Amonetize-AP [PUP]
100.00%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize, not-a-virus:AdWare.Win32.Amonetize
100.00%

Avira AntiVirus
ADWARE/Adware.Gen2
100.00%

Sophos
Amonetize
100.00%

AhnLab V3 Security
PUP/Win32.Amonetiz
100.00%

ESET NOD32
Win32/Amonetize.AJ (variant)
100.00%

Dr.Web
Adware.Downware.2467
90.00%

Baidu Antivirus
Adware.Win32.Amonetize
90.00%

Qihoo 360 Security
Win32/Virus.Adware.932, Win32/Virus.Adware.389
70.00%

Trend Micro House Call
TROJ_GEN.F47V0404, TROJ_GEN.R0CBH05DA14, TROJ_GEN.F47V0408, TROJ_GEN.R0CBH07D714, TROJ_GEN.R0CBH07D914, TROJ_GEN.F47V0407
70.00%

Fortinet FortiGate
Riskware/Amonetize, Adware/Amonetize
60.00%

Reason Heuristics
Threat.Win.Reputation.IMP
60.00%

McAfee
Artemis!96235EA3403B, Artemis!C406CE1BA46C, Artemis!4FBEE8825D47, Artemis!362D15671FD1, RDN/Generic PUP.x!c2d
50.00%

McAfee Web Gateway
Artemis!96235EA3403B, Artemis!C406CE1BA46C, Artemis!4FBEE8825D47, Artemis!362D15671FD1, RDN/Generic PUP.x!c2d
50.00%

The domain www.essentialdownload.com has been seen to resolve to the following 8 IP addresses.

March 3, 2016

ip-50-63-202-104.ip.secureserver.net
May 3, 2015

ec2-50-17-209-45.compute-1.amazonaws.com
May 30, 2014

ec2-23-21-228-251.compute-1.amazonaws.com
May 30, 2014

ec2-107-20-210-63.compute-1.amazonaws.com
May 30, 2014

ec2-50-17-206-16.compute-1.amazonaws.com
May 30, 2014

ec2-107-21-115-114.compute-1.amazonaws.com
April 11, 2014

ec2-54-235-68-127.compute-1.amazonaws.com
April 11, 2014

File downloads found at URLs served by www.essentialdownload.com.

 
Latest 30 of 37 download URLs

The following 13 files have been seen to comunicate with www.essentialdownload.com in live environments.

URL:
http://www.essentialdownload.com/

Title:
“Buy Domain Names- Find a Premium Domain & Open Your Doors, BuyDomains.com”

Description:
“Buy a domain and see how a premium domain can be the best investment. Your business starts here. Buy a domain today.”

Web server:
Apache/2.4.6 (CentOS) PHP/5.6.8 (PHP/5.6.8)