www.ftdownloader.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.ftdownloader.net is registered by proxy through GODADDY.COM, LLC and was originally registered in November of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Remove Malware from www.ftdownloader.net - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Dublin City, Ireland (IE)

Create date:
Tuesday, November 27, 2012

Expires date:
Friday, November 27, 2015

Updated date:
Friday, November 28, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.CoolMirageltd.t, PUP.HARASANPRAPAPON.X, PUP.Installer.CoolMirage.N, PUP.CoolMirage.e, PUP.CoolMirage.BB, PUP.InstallLabltd.Q, PUP.CoolMirageltd.G, PUP.TerraFirmaInternetConsulting.N, PUP.CoolMirage.Installer (M), PUP.TanjaMatkovic.Installer (M)
100.00%

Malwarebytes
PUP.Adware.Agent, PUP.Optional.OneClickDownloader.A
66.67%

VIPRE Antivirus
Iminent, BubbleDock, CoolMirage Ltd, Conduit, Threat.4784938
58.33%

Dr.Web
Adware.Downware.794, Adware.Downware.1263, Adware.Yontoo.11, Threat.Undefined
50.00%

Sophos
FT Downloader, CoolMirage, 1 Click Downloader
50.00%

McAfee
Adware-SweetIM, Artemis!67F3A421F22D, Artemis!98D9B6ED82E9
41.67%

Qihoo 360 Security
Win32/Virus.Adware.47b, Malware.QVM06.Gen
33.33%

McAfee Web Gateway
Artemis!67F3A421F22D, Artemis!98D9B6ED82E9, BehavesLike.Win32.AdwareSweet.dc
33.33%

avast!
NSIS:Oneclick-AA [PUP], Downloader-TPG [PUP], Downloader-UHI [PUP]
25.00%

NANO AntiVirus
Trojan.Script.Downware.cujzax
25.00%

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
25.00%

Avira AntiVirus
APPL/CoolMirage.Gen6
25.00%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
25.00%

Panda Antivirus
PUP/MultiToolbar.A
25.00%

Trend Micro House Call
TROJ_GEN.F47V0416, TROJ_GEN.F47V0412, TROJ_GEN.F47V0315
25.00%

The domain www.ftdownloader.net has been seen to resolve to the following 6 IP addresses.

ec2-54-246-121-152.eu-west-1.compute.amazonaws.com
November 10, 2015

ec2-54-246-120-161.eu-west-1.compute.amazonaws.com
June 30, 2015

ec2-184-169-157-32.us-west-1.compute.amazonaws.com
February 10, 2015

ec2-50-18-168-176.us-west-1.compute.amazonaws.com
November 18, 2014

ec2-54-241-253-59.us-west-1.compute.amazonaws.com
September 21, 2014

ec2-184-169-175-49.us-west-1.compute.amazonaws.com
May 1, 2014

File downloads found at URLs served by www.ftdownloader.net.

1 / 68      (Adware)

9 / 68      (Adware)

10 / 68    (Adware)
http://www.ftdownloader.net/.../DownloadSetup.exe  (cheba_zohra_and_cheb_hamid_ana_wiyak.exe)

9 / 68      (Adware)

10 / 68    (Adware)

8 / 68      (Adware)

6 / 68      (Adware)
http://www.ftdownloader.net/.../DownloadSetup.exe  (c79742fdeddb4d19aca69bd347612b8f)

5 / 68      (Adware)

Remove Malware from www.ftdownloader.net - Powered by Reason Core Security