youtubedownload.altervista.org

Banzai Media S.R.L.

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Nuremberg, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
Tucows Inc.

Server location:
Bayern, Germany (DE)

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.GreentreeApplicationsSRL.J, PUP.Optional.Installer.GreentreeApplicationsSRL.I, PUP.Optional.GreentreeApplicationsSRL.N, PUP.YTD.Optional.Installer.Meta (L), Win32.Generic, PUP.Greentree.YTD.Installer.Meta (M), PUP.YTD.Installer.Installer.Meta (M), PUP.Greentree.YTD.Installer.Installer.Meta (M)
93.33%

ESET NOD32
Win32/Toolbar.Widgi (variant), Win32/Bundled.Toolbar.Ask (variant), Win32/Bundled.Toolbar.Ask.G potentially unsafe (variant)
60.00%

Dr.Web
Adware.Downware.1417, Adware.BGuard.24, Adware.Spigot.16, Threat.Undefined, Adware.Downware.10873
53.33%

Malwarebytes
PUP.Optional.Spigot.A, PUP.Optional.APNToolBar.A
53.33%

McAfee
Artemis!A5CD7E1F5913, Artemis!477A9E92623F, Artemis!97AC0359A345, Artemis!1816C1C5B6F4, Artemis!C0841F98FF22, Artemis!8A5AE67E0CA6
46.67%

McAfee Web Gateway
Artemis!A5CD7E1F5913
46.67%

AVG
Skodna.Generic_c, Greentree, Downloader
46.67%

Bkav FE
W32.Clod16b.Trojan, W32.Clod6c3.Trojan, W32.Clod5b0.Trojan, W32.HfsAdware
40.00%

Trend Micro House Call
TROJ_GEN.F47V1112, TROJ_GEN.F47V0816, TROJ_GEN.F47V0904, TROJ_GEN.F47V0121, TROJ_GEN.F47V0213, TROJ_GEN.F47V0430, Suspicious_GEN.F47V1218
40.00%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
40.00%

Rising Antivirus
NS:Malware.Install!1.9F21, PE:Trojan.Win32.Generic.172F5263!388977251
36.67%

NANO AntiVirus
Trojan.Win32.Downware.ctuoeb, Riskware.Win32.Bundled.dacits
23.33%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4721115
20.00%

avast!
Win32:Adware-gen [Adw], Win32:SaliCode
20.00%

Kaspersky
not-a-virus:AdWare.MSIL.RocketTab, Virus.Win32.Sality
20.00%

The domain youtubedownload.altervista.org has been seen to resolve to the following 3 IP addresses.

November 6, 2015

November 6, 2015

ns201.altervista.org
March 14, 2014

File downloads found at URLs served by youtubedownload.altervista.org.

11 / 68    (PUP)
http://youtubedownload.altervista.org/.../YTDSetup.exe  (9aca8c6f76c8a0aec8167431cdc11689)

6 / 68      (Malware)

7 / 68      (PUP)
http://youtubedownload.altervista.org/.../SetupYTD.exe  (477a9e92623f05e4e2b25ba5bf072dc0)

2 / 68      (PUP)

1 / 68      (PUP)

26 / 68    (PUP)

2 / 68      (PUP)

3 / 68      (PUP)

The following 2 files have been seen to comunicate with youtubedownload.altervista.org in live environments.

URL:
http://youtubedownload.altervista.org/

Google Analytics:
UA-26470099

Title:
“Free Youtube Downloader | YTD Youtube Downloader”

Description:
“YTD Youtube Downloader lets you save videos from tons of websites and play them on your computer. Best of all, it’s free! Available for Windows & Mac”

Web server:
cloudflare-nginx

Facebook:
Likes:  14,177
Shares:  17,228
Comments:  5,196

Statistics are for the previous month.