a.postumes.com

Dastan Isaev

Domain Information

The domain a.postumes.com registered by Dastan Isaev was initially registered in March of 2015 through TLD REGISTRAR SOLUTIONS LTD. Currently this domain has been known to host various forms of malware. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
TLD REGISTRAR SOLUTIONS LTD

Server location:
Oregon, United States (US)

Create date:
Friday, March 20, 2015

Expires date:
Sunday, March 20, 2016

Updated date:
Tuesday, March 24, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP
100.00%

Dr.Web
Trojan.DownLoader13.35876, Trojan.DownLoader13.35534
50.00%

AVG
Adware Generic6.AYYI, Adware Generic6.AYYN
50.00%

McAfee
Program.MultiPlug-FWG, MultiPlug-FAC
50.00%

avast!
Win32:MultiPlug-ZC [PUP], Win32:FakeDownload-F [PUP]
50.00%

Sophos
PUA 'MultiPlug' (of type Adware)
50.00%

ESET NOD32
Win32/Adware.MultiPlug.MF application
50.00%

Zillya! Antivirus
Adware.MultiPlugGen.Win32.1
50.00%

K7 AntiVirus
Unwanted-Program
50.00%

Avira AntiVirus
TR/Crypt.XPACK.Gen
50.00%

AhnLab V3 Security
PUP/Win32.MultiPlug
50.00%

Vba32 AntiVirus
suspected of Heur.Malware-Cryptor.Multiplug
50.00%

IKARUS anti.virus
PUA.Win32.InstalleRex
50.00%

Fortinet FortiGate
Riskware/Generic.AC.4386, Riskware/Badur
50.00%

Lavasoft Ad-Aware
Gen:Variant.Zusy.145662
25.00%

The domain a.postumes.com has been seen to resolve to the following 4 IP addresses.

ec2-52-27-23-115.us-west-2.compute.amazonaws.com
July 1, 2015

ec2-52-26-142-209.us-west-2.compute.amazonaws.com
July 1, 2015

ec2-52-11-167-137.us-west-2.compute.amazonaws.com
July 1, 2015

ec2-52-10-67-234.us-west-2.compute.amazonaws.com
July 1, 2015

File downloads found at URLs served by a.postumes.com.

The following file have been seen to comunicate with a.postumes.com in live environments.

URL:
http://a.postumes.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
openresty