direct7zip.com

Contact Privacy Inc. Customer 0135083022  (Proxy Registrant)

Domain Information

The domain direct7zip.com is registered by proxy through TUCOWS DOMAINS INC. and was originally registered in July of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
TUCOWS DOMAINS INC.

Server location:
Virginia, United States (US)

Create date:
Monday, July 8, 2013

Expires date:
Friday, July 8, 2016

Updated date:
Friday, August 7, 2015

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Adknowledge.Fileangels.Bundler (M), PUP.Adknowledge.ComputeClient.Installer (M), PUP.Adknowledge.BootCompute.Bundler (M), PUP.MindAd.MindAdMedia.Installer (M), PUP.DownloadAdmin.EBooksMedia.Installer (M), PUP.Softpulse.VolvanPremium.Installer (M), PUP.Vittalia.InstallA.Installer (M), PUP.Adknowledge.ComputeC.Bundler (M), PUP.Adknowledge.BootComp.Bundler (M), PUP.Adknowledge.TigerDow.Bundler (M), PUP.Adknowledge.ComputeC.Installer (M), PUP.DownloadAdmin.EBooksMe.Installer (M), PUP.Downloadius.Web.Installer (M), PUP.Adknowledge.INSTALLT.Installer (M), PUP.Softpulse.Softforc.Bundler (M), PUP.Adknowledge (M), PUP.DownloadAdmin (M)
97.96%

Malwarebytes
PUP.Optional.Mixxen.A, PUP.Optional.OptimunInstaller, PUP.Optional.GigaClicks.A
6.12%

Sophos
Generic PUA JC, iBryte Premium Installer, PUA.iBryte Optimum Installer
6.12%

Comodo Security
ApplicUnwnt, Application.Win32.AgentCV.HWYE
6.12%

Avira AntiVirus
ADWARE/Adware.Gen7, ADWARE/iBryte.Gen4, TR/Kazy.439479.2
6.12%

McAfee
Artemis!FB3C282C19D4, IBryte-FRT, Artemis!0FF2B0F7AD04
6.12%

Fortinet FortiGate
Adware/PullUpdate, W32/Zbot.AAN!tr, W32/Malware_fam.NB
6.12%

Trend Micro House Call
Suspicious_GEN.F47V0109, TROJ_CLIKUG.A
4.08%

ESET NOD32
MSIL/Adware.PullUpdate.J.gen (variant), Win32/AdWare.iBryte.BK (variant)
4.08%

Baidu Antivirus
Adware.MSIL.PullUpdate, Trojan.Win32.Clikug
4.08%

VIPRE Antivirus
Threat.4778314
4.08%

avast!
Win32:Adware-gen [Adw]
4.08%

G Data
Win32.Adware.IBryte, Gen:Variant.Kazy.439479
4.08%

AVG
AdPlugin, Adware AdPlugin
4.08%

Kaspersky
Trojan.Win32.Badur, Trojan-Clicker.Win32.Agent
4.08%

The domain direct7zip.com has been seen to resolve to the following 4 IP addresses.

ec2-54-210-180-22.compute-1.amazonaws.com
April 1, 2016

ec2-54-84-187-203.compute-1.amazonaws.com
April 1, 2016

ec2-52-22-129-36.compute-1.amazonaws.com
January 31, 2016

ec2-52-20-41-248.compute-1.amazonaws.com
January 31, 2016

File downloads found at URLs served by direct7zip.com.

 
Latest 30 of 57 download URLs

URL:
http://direct7zip.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Microsoft-IIS/8.5 (ASP.NET) (Version: 4.0.30319)