www.immediatelydownload.com

China Capital Investment Limited

Domain Information

The domain www.immediatelydownload.com registered by China Capital Investment Limited was initially registered in May of 2015 through Moniker Online Services. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
NAMESALACARTE.COM LLC

Server location:
Virginia, United States (US)

Create date:
Saturday, May 02, 2015

Expires date:
Monday, May 02, 2016

Updated date:
Monday, March 07, 2016

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Win.Reputation, Threat.Win.Reputation.IMP, PUP.Amonetize.Bundler (M)
96.77%

NANO AntiVirus
Riskware.Win32.Downware.cyusqp, Riskware.Win32.Amonetize.czmxgw, Riskware.Win32.Amonetize.cyxkne, Riskware.Win32.Amonetize.czcqbh
90.32%

AVG
Generic_r
90.32%

avast!
Win32:Amonetize-BJ [PUP], Win32:Amonetize-BK [PUP]
87.10%

Avira AntiVirus
ADWARE/Adware.Gen2
87.10%

McAfee Web Gateway
PUP-FBM!B8C170DC2B13, PUP-FBM!406ED99106D2, PUP-FBM!8ED066183EF9, PUP-FBM!8888DD336443, PUP-FBM!0EE6DF391446, PUP-FBM!EB6601E4918E
87.10%

McAfee
PUP-FBM!B8C170DC2B13, PUP-FBM!406ED99106D2, PUP-FBM!8ED066183EF9, PUP-FBM!8888DD336443, PUP-FBM!0EE6DF391446, PUP-FBM!EB6601E4918E, PUP-FBM!7756659E6C8C, PUP-FBM!CD0BF83F430A, PUP-FBM!ADB7B4A4B58A, PUP-FBM!CDC1DAC06AE5, PUP-FBM!6043F9586836, PUP-FBM!56AD118C76AC, PUP-FBM!3B15E3831B43, PUP-FBM!838E942A7DDD, PUP-FBM!26C1425072D5, PUP-FBM!A041FA631138, PUP-FBM!2F4FA9A6BA3F, PUP-FBM!DFB8C8089E7D, PUP-FBM!922C02FC27B3, PUP-FBM!C37124F00465, PUP-FBM!CDF42D7CB4C1, PUP-FBM!626A8AB0B10A, PUP-FBM!51CFB7C6B99D
83.87%

Malwarebytes
PUP.Optional.Amonetize, PUP.Optional.Monetizer
83.87%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize
83.87%

Sophos
Amonetize
83.87%

AhnLab V3 Security
PUP/Win32.Amonetiz
83.87%

ESET NOD32
Win32/Amonetize.AS (variant), Win32/Amonetize.AS potentially unwanted (variant)
83.87%

VIPRE Antivirus
Amonetize, Trojan.Win32.Generic
77.42%

Baidu Antivirus
Adware.Win32.Amonetize
77.42%

Dr.Web
Adware.Downware.3925, Adware.Downware.4411, Trojan.Amonetize.353
74.19%

The domain www.immediatelydownload.com has been seen to resolve to the following 5 IP addresses.

192.230.92.93.ip.incapdns.net
August 8, 2016

April 9, 2016

May 3, 2015

209.222.14.3.choopa.net
February 23, 2015

ec2-54-225-180-137.compute-1.amazonaws.com
June 9, 2014

File downloads found at URLs served by www.immediatelydownload.com.

 
Latest 30 of 39 download URLs

The following 9 files have been seen to comunicate with www.immediatelydownload.com in live environments.

URL:
http://www.immediatelydownload.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx/1.8.1