www.ftdownloader.net

N/A

Domain Information

The domain www.ftdownloader.net registered by N/A was initially registered in February of 2016 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Dublin City, Ireland (IE)

Create date:
Monday, February 15, 2016

Expires date:
Wednesday, February 15, 2017

Updated date:
Monday, February 15, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.CoolMirageltd.t, PUP.HARASANPRAPAPON.X, PUP.Installer.CoolMirage.N, PUP.HARASANPRAPAPON.BB, PUP.CoolMirage.e, PUP.CoolMirage.BB, PUP.CoolMirageltd.G, PUP.TerraFirmaInternetConsulting.N, PUP.CoolMirage.Installer (M), PUP.TanjaMatkovic.Installer (M), PUP.TerraFir.Installer (M), PUP.Crossrider.HARASANP.Installer (M), PUP (M)
100.00%

Malwarebytes
PUP.Adware.Agent, PUP.Optional.OneClickDownloader.A
36.67%

VIPRE Antivirus
Iminent, BubbleDock, CoolMirage Ltd, Conduit, Threat.4784938
33.33%

Dr.Web
Adware.Downware.794, Adware.Downware.1263, Adware.Yontoo.11, Threat.Undefined, Adware.Yontoo.4
26.67%

Sophos
FT Downloader, CoolMirage, 1 Click Downloader
23.33%

McAfee
Adware-SweetIM, Artemis!67F3A421F22D, Artemis!98D9B6ED82E9, Artemis!9D2FE1D54B93
20.00%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
16.67%

Qihoo 360 Security
Win32/Virus.Adware.47b, Malware.QVM06.Gen
16.67%

McAfee Web Gateway
Artemis!67F3A421F22D, Artemis!98D9B6ED82E9, Artemis!9D2FE1D54B93, BehavesLike.Win32.AdwareSweet.dc
16.67%

Panda Antivirus
PUP/MultiToolbar.A
13.33%

Trend Micro House Call
TROJ_GEN.F47V0416, TROJ_GEN.F47V0412, TROJ_GEN.F47V0315, TROJ_GEN.F47V0404
13.33%

avast!
NSIS:Oneclick-AA [PUP], Downloader-TPG [PUP], Downloader-UHI [PUP]
10.00%

NANO AntiVirus
Trojan.Script.Downware.cujzax
10.00%

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
10.00%

Avira AntiVirus
APPL/CoolMirage.Gen6
10.00%

The domain www.ftdownloader.net has been seen to resolve to the following 9 IP addresses.

August 25, 2016

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
June 26, 2016

April 11, 2016

ec2-54-246-121-152.eu-west-1.compute.amazonaws.com
November 10, 2015

ec2-54-246-120-161.eu-west-1.compute.amazonaws.com
June 30, 2015

ec2-184-169-157-32.us-west-1.compute.amazonaws.com
February 10, 2015

ec2-50-18-168-176.us-west-1.compute.amazonaws.com
November 18, 2014

ec2-54-241-253-59.us-west-1.compute.amazonaws.com
September 21, 2014

ec2-184-169-175-49.us-west-1.compute.amazonaws.com
May 1, 2014

File downloads found at URLs served by www.ftdownloader.net.

10 / 68    (Adware)

1 / 68      (Adware)
http://www.ftdownloader.net/.../_.exe  (3392c65fb379eefe5706d78e011b342b)

10 / 68    (Adware)

6 / 68      (Adware)
http://www.ftdownloader.net/.../QbjaybnqFrghc.exe  (fruko_y_sus_tesos_pa_goza_con_fruko.exe)

10 / 68    (Adware)

4 / 68      (Adware)
http://www.ftdownloader.net/.../DownloadSetup.exe  (uyirvani_tamil_dubbed_movie.exe)

1 / 68      (Adware)

9 / 68      (Adware)

9 / 68      (Adware)

10 / 68    (Adware)

 
Latest 30 of 36 download URLs

The following 215 files have been seen to comunicate with www.ftdownloader.net in live environments.

TCP » 54.72.9.51:80

 
Latest 20 of 219 files

URL:
http://www.ftdownloader.net/

Google Analytics:
UA-48689684

Title:
“ftdownloader.net”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx

30 of 618 related domains