best-new-zip-my.info

Ivan Prihodko

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
Domain.com,LLC (R656-LRMS)

Server location:
Oregon, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer.Q, PUP.Optional.Installer.X, PUP.Installer.SergeyPetrov.K, Adware.WebPick.Installer.S, Adware.WebPick.Installer.V, Adware.WebPick.Installer.K, Adware.WebPick.Installer.X, Adware.WebPick.Installer.BB, Adware.WebPick.Installer.H, Adware.WebPick.Installer.e, Adware.WebPick.Installer.R, Adware.WebPick.Installer.g, Adware.WebPick.Installer.w, Adware.WebPick.Installer.I, Adware.WebPick.Installer.j, Adware.WebPick.Installer.q, Adware.AdInjector.Installer.WebPick, Adware.WebPick.Installer (M), Adware (M)
100.00%

Malwarebytes
PUP.Optional.Installrex, PUP.Optional.InstalleRex, PUP.Optional.Tarma, PUP.Optional.Installex
87.50%

avast!
Win32:InstalleRex-AI [PUP], Win32:InstalleRex-BI [PUP], Win32:InstalleRex-AR [PUP], Win32:InstalleRex-Y [PUP], Win32:InstalleRex-AH [PUP]
87.50%

Kaspersky
not-a-virus:Downloader.Win32.AdLoad, Trojan.Win32.AntiFW, not-a-virus:HEUR:Downloader.Win32.AdLoad
87.50%

Comodo Security
Application.Win32.InstalleRex.KG
87.50%

Dr.Web
Adware.Downware.1541, Trojan.WebPick.29, Adware.Downware.1719, Adware.Downware.1442, Adware.Downware.2108, Trojan.WebPick.2735
87.50%

VIPRE Antivirus
Trojan.Win32.Generic, Installerex/WebPick, Threat.4150696
87.50%

Avira AntiVirus
Adware/InstallRex.X, TR/Kazy.324119.11, Adware/InstallRex.bza, ADWARE/InstallRex.Gen, Adware/Adload.ger, TR/AntiFW.b.106
87.50%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud), Win32.Troj.AntiFW.b.(kcloud), Win32.Troj.DownAdLoad.g.(kcloud), Win32.Troj.DownAdLoad.f.(kcloud)
87.50%

Vba32 AntiVirus
Downloader.AdLoad, Downware.TSU, AdWare.Agent
87.50%

AVG
MalSign.Generic, Skodna.Generic, Skodna.Bundle, Trojan horse Crypt_s.GAB, Adware Skodna.Bundle, InstallRex
87.50%

K7 Gateway Antivirus
Unwanted-Program , Trojan
83.33%

Sophos
InstallRex, PUA 'InstallRex'
83.33%

G Data
Trojan.Generic.10396428, Win32.Application.InstalleRex, Application.Generic.621656, Trojan.Generic.11548988, Win32.Application.EZDownloader
83.33%

NANO AntiVirus
Trojan.Win32.AntiFW.cvgqot, Riskware.Win32.Downware.cscobj, Riskware.Win32.Downware.crfmjd, Riskware.Win32.Downware.ctkpgp
83.33%

The domain best-new-zip-my.info has been seen to resolve to the following 3 IP addresses.

148.162.96.66.static.eigbox.net
September 5, 2014

ec2-54-186-255-26.us-west-2.compute.amazonaws.com
April 4, 2014

ec2-54-201-215-30.us-west-2.compute.amazonaws.com
January 16, 2014

File downloads found at URLs served by best-new-zip-my.info.

 
Latest 30 of 48 download URLs

The following file have been seen to comunicate with best-new-zip-my.info in live environments.

URL:
http://best-new-zip-my.info/

Title:
“Domain.com”

Description:
“Small business web hosting offering additional business services such as: domain name registrations, email accounts, web services, FrontPage help, online community resources and various small business solutions.”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Apache/2