cdn.nextadtomorrowfiles.com

Communigal Communication Ltd

Domain Information

The domain cdn.nextadtomorrowfiles.com registered by Communigal Communication Ltd was initially registered in May of 2015 through GAL COMMUNICATION (COMMUNIGAL) LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
GAL COMMUNICATION (COMMUNIGAL) LTD.

Server location:
Oregon, United States (US)

Create date:
Tuesday, May 26, 2015

Expires date:
Thursday, May 26, 2016

Updated date:
Tuesday, May 26, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc., US

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.InstallX.Bundle, PUP.installCore.Installer, PUP.Win.Reputation, Threat.Win.Reputation.IMP, PUP.installCore.AVSoftware.Installer (M), PUP.TomorrowSoftware.SpiralMedia.Bundler (M), PUP.Downloadius.Downloadious.Installer (M), PUP.InstallCore.S (M), PUP.installCore.AVSoftwa.Installer (M), PUP.Softpulse.DIGITALP.Bundler (M), PUP.InstallCore.RES (M), PUP.installCore (M)
100.00%

Dr.Web
Trojan.InstallCore.642, Trojan.Vittalia.823
27.66%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
27.66%

K7 AntiVirus
Adware
27.66%

AVG
InstallCore, Generic
27.66%

Baidu Antivirus
Adware.Win32.InstallCore
27.66%

ESET NOD32
Win32/InstallCore.ZN potentially unwanted application, Win32/InstallCore.YQ potentially unwanted application
25.53%

Avira AntiVirus
PUA/InstallCore.lop
25.53%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696
25.53%

McAfee
Trojan.Artemis!2FC907089279, Artemis!10444FA4A210
25.53%

Bkav FE
W32.HfsAdware
25.53%

Malwarebytes
PUP.Optional.InstallCore
25.53%

G Data
Win32.Application.InstallCore.EG
25.53%

Qihoo 360 Security
Win32/Virus.2c8
23.40%

Trend Micro House Call
TROJ_GEN.F47V0824, Suspicious_GEN.F47V0602
4.26%

The domain cdn.nextadtomorrowfiles.com has been seen to resolve to the following 23 IP addresses.

ec2-52-33-25-64.us-west-2.compute.amazonaws.com
September 4, 2016

ec2-52-39-140-133.us-west-2.compute.amazonaws.com
August 15, 2016

ec2-52-27-121-127.us-west-2.compute.amazonaws.com
August 10, 2016

ec2-52-27-160-135.us-west-2.compute.amazonaws.com
July 31, 2016

ec2-52-10-85-80.us-west-2.compute.amazonaws.com
July 30, 2016

ec2-54-68-191-252.us-west-2.compute.amazonaws.com
July 21, 2016

ec2-54-148-219-152.us-west-2.compute.amazonaws.com
June 30, 2016

ec2-52-24-198-8.us-west-2.compute.amazonaws.com
June 23, 2016

ec2-52-40-74-243.us-west-2.compute.amazonaws.com
May 27, 2016

ec2-52-34-254-156.us-west-2.compute.amazonaws.com
May 26, 2016

ec2-54-148-241-40.us-west-2.compute.amazonaws.com
May 25, 2016

ec2-52-35-246-224.us-west-2.compute.amazonaws.com
May 20, 2016

ec2-52-25-167-148.us-west-2.compute.amazonaws.com
May 16, 2016

ec2-52-35-220-181.us-west-2.compute.amazonaws.com
April 11, 2016

ec2-52-32-132-26.us-west-2.compute.amazonaws.com
April 6, 2016

ec2-54-191-197-143.us-west-2.compute.amazonaws.com
April 3, 2016

ec2-52-10-249-85.us-west-2.compute.amazonaws.com
February 26, 2016

ec2-54-191-172-222.us-west-2.compute.amazonaws.com
February 16, 2016

ec2-54-148-9-47.us-west-2.compute.amazonaws.com
February 11, 2016

ec2-52-27-150-245.us-west-2.compute.amazonaws.com
January 31, 2016

ec2-54-200-215-92.us-west-2.compute.amazonaws.com
January 4, 2016

ec2-52-27-109-25.us-west-2.compute.amazonaws.com
June 30, 2015

ec2-52-25-139-170.us-west-2.compute.amazonaws.com
June 18, 2015

File downloads found at URLs served by cdn.nextadtomorrowfiles.com.

 
Latest 30 of 50 download URLs