www.greatappsdownload.com

ADLSoft  (via a Proxy Registrant)

Domain Information

The domain www.greatappsdownload.com is registered by proxy through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM and was originally registered in June of 2013. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter. The domain is associated with the publisher ADLSoft who is located in Tel Aviv, Israel.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Dublin City, Ireland (IE)

Create date:
Monday, June 03, 2013

Expires date:
Friday, June 03, 2016

Updated date:
Wednesday, May 27, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (88% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Coolapptech.Installer (M), PUP.installCore.Coolappt.Installer (M), PUP.InstallCore.FC.Installer (M), PUP.installCore.CoolAppD.Installer (M), PUP.installCore (M), PUP.NewMedia.NMH (M)
87.76%

ESET NOD32
Win32/Kryptik.BWJC trojan, Win32/InstallCore.D potentially unwanted application, Win32/InstallCore.BX potentially unwanted application, Win32/InstallCore.BY potentially unwanted application
53.06%

avast!
Win32:Adware-gen [Adw], Win32:Dropper-gen [Drp]
34.69%

Dr.Web
Trojan.Packed.24524, Trojan.Packed.31388, Adware.InstallCore.132
28.57%

F-Prot
W32/InstallCore.R.gen
14.29%

VIPRE Antivirus
InstallCore, Threat.4786018, Threat.4150696
12.24%

AVG
Adware InstallCore.VH
12.24%

Norman
Application.Generic.931548, Gen:Variant.Adware.Strictor.66006
10.20%

Sophos
Install Core Click run software, PUA 'Install Core Click run software'
6.12%

Emsisoft Anti-Malware
Application.Generic.931548
6.12%

F-Secure
Riskware.Application.Generic.931548, Variant.Adware.Strictor
4.08%

Malwarebytes
PUP.Optional.BundleInstaller.A
2.04%

Trend Micro House Call
TROJ_GEN.F47V0929
2.04%

Avira AntiVirus
ADWARE/InstallCore.Gen7
2.04%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
2.04%

The domain www.greatappsdownload.com has been seen to resolve to the following 9 IP addresses.

ec2-54-194-169-19.eu-west-1.compute.amazonaws.com
March 1, 2015

ec2-54-72-121-228.eu-west-1.compute.amazonaws.com
March 1, 2015

ec2-54-229-24-120.eu-west-1.compute.amazonaws.com
March 1, 2015

ec2-54-229-168-240.eu-west-1.compute.amazonaws.com
May 1, 2014

ec2-54-229-130-160.eu-west-1.compute.amazonaws.com
May 1, 2014

ec2-54-229-74-109.eu-west-1.compute.amazonaws.com
May 1, 2014

ec2-54-194-48-236.eu-west-1.compute.amazonaws.com
January 25, 2014

ec2-54-229-185-225.eu-west-1.compute.amazonaws.com
January 25, 2014

ec2-54-194-102-99.eu-west-1.compute.amazonaws.com
January 25, 2014

File downloads found at URLs served by www.greatappsdownload.com.

1 / 68      (inconclusive)

1 / 68      (Adware)

1 / 68      (inconclusive)

4 / 68      (Adware)

9 / 68      (Adware)

 
Latest 30 of 139 download URLs