d3kj6o4rxau601.cloudfront.net

Amazon.com, Inc

Domain Information

The domain d3kj6o4rxau601.cloudfront.net registered by Amazon.com, Inc was initially registered in April of 2008 through MARKMONITOR INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
MARKMONITOR INC.

Server location:
Virginia, United States (US)

Create date:
Friday, April 25, 2008

Expires date:
Tuesday, April 25, 2017

Updated date:
Tuesday, February 25, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.FuyuanZhou, PUP.Installer.FuyuanZhou, Threat.Installer.FuyuanZhou, PUP.FuyuanZhou (M), PUP.ELEX.YuxinWANG (M), PUP.ELEX.SkytouchTechnologyCo (M), PUP.Thinknice.ThinkniceCo (M), PUP.CHAODONGXIAO (M), Threat.Win.Reputation.IMP, PUP.ELEX.Skytouch (M)
98.00%

Baidu Antivirus
Adware.Win32.ELEX, Adware.Win32.Elex
36.00%

Dr.Web
Adware.Mutabaha.179, Adware.Mutabaha.190, Adware.Mutabaha.219, Adware.Mutabaha.359, Adware.Mutabaha.361, Adware.Mutabaha.859, Adware.Mutabaha.873
28.00%

K7 AntiVirus
Trojan , Adware
26.00%

VIPRE Antivirus
BehavesLike.Win32.Malware.sfd (mx-v), Threat.4726263, Trojan.Win32.Generic, Threat.219451, SkyTouch, Elex Installer, Threat.4788726
24.00%

Malwarebytes
PUP.Optional.IStartSurf.A, PUP.Optional.LuckySearches.A, PUP.Optional.MyStartSearch.A, PUP.Optional.OurSeaching.A, PUP.Optional.YourSearching.ShrtCln
22.00%

ESET NOD32
Win32/ELEX.CF potentially unwanted (variant), Win32/ELEX.CE potentially unwanted (variant), Win32/ELEX.FK potentially unwanted (variant)
22.00%

ESET NOD32
Win32/ELEX.CF potentially unwanted application, Win32/ELEX.DY potentially unwanted application, Win32/ELEX.FG potentially unwanted application, Win32/ELEX.FC potentially unwanted application
20.00%

AVG
Downloader, Generic, Generic_r, Adware AdPlugin.FQP, Elex
16.00%

herdProtect (fuzzy)
a variant of a09dd99368cc38b739bbd5d2ce02eb05d63c82b6, a variant of 161164687b487d4f730c7f9c09a4d4df8a561e48, a variant of e45e72b9b6592a0d21baa633a08d5b7954138b86
14.00%

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen, QVM41.1.Malware.Gen
14.00%

Bkav FE
W32.HfsAdware
12.00%

avast!
Win32:Adware-gen [Adw], Win32:Oncer, Win32:Malware-gen
10.00%

Sophos
PUA 'Elex' (of type Adware)
8.00%

Avira AntiVirus
TR/Elex.321632.2, PUA/Subtab.Gen7, TR/Crypt.XPACK.Gen
8.00%

The domain d3kj6o4rxau601.cloudfront.net has been seen to resolve to the following 161 IP addresses.

server-52-84-125-185.iad16.r.cloudfront.net
July 21, 2016

server-52-84-125-28.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-27.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-198.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-165.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-152.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-110.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-96.iad16.r.cloudfront.net
July 17, 2016

server-52-84-125-46.iad16.r.cloudfront.net
July 17, 2016

server-52-85-131-125.iad53.r.cloudfront.net
June 27, 2016

server-52-85-131-88.iad53.r.cloudfront.net
June 27, 2016

server-52-85-131-39.iad53.r.cloudfront.net
June 27, 2016

server-52-85-131-28.iad53.r.cloudfront.net
June 27, 2016

server-52-85-131-26.iad53.r.cloudfront.net
June 27, 2016

server-52-85-131-175.iad53.r.cloudfront.net
June 27, 2016

server-52-85-131-150.iad53.r.cloudfront.net
June 27, 2016

server-52-85-142-147.iad12.r.cloudfront.net
May 18, 2016

server-52-85-131-79.iad53.r.cloudfront.net
May 17, 2016

server-52-85-131-64.iad53.r.cloudfront.net
May 17, 2016

server-52-85-131-235.iad53.r.cloudfront.net
May 17, 2016

server-52-85-131-229.iad53.r.cloudfront.net
May 17, 2016

server-52-85-131-189.iad53.r.cloudfront.net
May 17, 2016

server-52-85-131-174.iad53.r.cloudfront.net
May 17, 2016

server-52-85-142-160.iad12.r.cloudfront.net
May 17, 2016

server-52-85-142-134.iad12.r.cloudfront.net
May 17, 2016

server-52-85-142-47.iad12.r.cloudfront.net
May 17, 2016

server-52-85-142-34.iad12.r.cloudfront.net
May 17, 2016

server-52-85-142-13.iad12.r.cloudfront.net
May 17, 2016

server-52-85-142-200.iad12.r.cloudfront.net
May 17, 2016

server-52-85-142-168.iad12.r.cloudfront.net
May 17, 2016

 
Showing 30 of 161 IP Addresses

File downloads found at URLs served by d3kj6o4rxau601.cloudfront.net.

1 / 68      (Adware)

14 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (PUP)

The following 42 files have been seen to comunicate with d3kj6o4rxau601.cloudfront.net in live environments.

 
Latest 20 of 111 files

URL:
http://d3kj6o4rxau601.cloudfront.net/

Network:
Amazon Cloudfront

SSL certificate subject:
CN=*.cloudfront.net, O="Amazon.com, Inc.", L=Seattle, S=Washington, C=US

SSL certificate issuer:
CN=Symantec Class 3 Secure Server CA - G4, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Web server:
AmazonS3