dl.s0ftpzivrubajjui.net

Domain Admin  (Proxy Registrant)

Domain Information

The domain dl.s0ftpzivrubajjui.net is registered by proxy through DYNADOT, LLC and was originally registered in November of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Registrar:
DYNADOT, LLC

Server location:
Dublin City, Ireland (IE)

Create date:
Monday, November 24, 2014

Expires date:
Thursday, November 24, 2016

Updated date:
Thursday, December 17, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.FIRSERIASL.G, PUP.Installer.FIRSERIASL.X, PUP.Installer.FIRSERIASL.N, PUP.Installer.FIRSERIASL.O, PUP.Installer.FIRSERIASL.P, PUP.Installer.FIRSERIASL.L, PUP.Solimba.FIRSERIA.Bundler (M), PUP.Solimba.Bundler, PUP.Solimba (M)
100.00%

VIPRE Antivirus
Threat.4782980, Threat.4758821, Adware.Firseria, Solimba
17.02%

Dr.Web
Trojan.DownLoader11.24441, Trojan.MulDrop5.34677
17.02%

Malwarebytes
PUP.Optional.Firseria
17.02%

Vba32 AntiVirus
Downware.Morstar
17.02%

AVG
Generic, BundleApp
17.02%

Panda Antivirus
Adware/Firseria
17.02%

Emsisoft Anti-Malware
Application.Bundler.Firseria.M, Trojan.Generic.11635227
17.02%

MicroWorld eScan
Application.Bundler.Firseria.M
17.02%

K7 AntiVirus
Unwanted-Program
17.02%

Agnitum Outpost
PUA.Solimba, PUA.Firseria
17.02%

Bitdefender
Application.Bundler.Firseria.M
17.02%

NANO AntiVirus
Riskware.Win32.Fiseria.ddnzzd, Trojan.Win32.MulDrop5.dcygsx
17.02%

Lavasoft Ad-Aware
Application.Bundler.Firseria.M
17.02%

Comodo Security
Application.Win32.Firseria.AFGH, Application.Win32.Firseria.MAP
17.02%

The domain dl.s0ftpzivrubajjui.net has been seen to resolve to the following 10 IP addresses.

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
April 3, 2016

December 28, 2014

November 29, 2014

a184-51-126-34.deploy.static.akamaitechnologies.com
September 6, 2014

a184-51-126-74.deploy.static.akamaitechnologies.com
September 6, 2014

a23-67-242-97.deploy.static.akamaitechnologies.com
August 12, 2014

a23-67-242-120.deploy.static.akamaitechnologies.com
August 12, 2014

a23-67-243-83.deploy.static.akamaitechnologies.com
August 12, 2014

August 12, 2014

a23-67-243-41.deploy.static.akamaitechnologies.com
August 12, 2014

File downloads found at URLs served by dl.s0ftpzivrubajjui.net.

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../File_installer.exe  (e2de1701c8a84aef3609e5333ff91da5)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../AVS_Media_Player.exe  (df344dc03ec5c0e0310ce5df58b218a0)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../Photo Art Studio.exe  (4c47c8933b6ab2eeadf2c85e07d702f7)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../Picasa.exe  (9cd866e0a6e3f87a4004cf5ad6b296e2)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../AVS_Media_Player.exe  (41cb7c6689beb14b188eded2181a9ed3)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../FLV_Media_Player.exe  (f7740a4f5c0097970e9d20e557dfa556)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../CDBurnerXP.exe  (b3a7e1e49fce09230d67cbe246a9723c)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../Nero Burning ROM.exe  (319b53bda75baa7cb28470872137d4f0)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../Power2Go.exe  (2cfba8bae24586f7fe1a6b015779eb12)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../Matlab.exe  (81b14aa2ea4afb49b24e2ff0e66c83eb)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../Flobo Photo.exe  (f774fb26e12eb994fdec758270568743)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../PES 2012.exe  (bcff557fd2584387bdec153f557fee4a)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../WhatsApp.exe  (e71a7dc945c73bd140f7330c2ee80635)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../Skype.exe  (45edc127489621300bbddb03c6420667)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../Clash of Clans.exe  (c7a5229b3328acec01c8b3d0d5215a94)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../UC Browser.exe  (238871d2b648a2078c2b530f8b27311c)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../WhatsApp pour PC.exe  (30fecd1a450ca834d8adfe947fd5109b)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../Hay Day.exe  (ed13fc7eb69772668d3c65d6be8a0c62)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../GarageBand.exe  (4e2f04c4c8c7342ab38607e7f0f5eca6)

0 / 68
http://dl.s0ftpzivrubajjui.net/n/.../Minecraft.exe  (2ee7c6da5dd91613311dada250b3fe39)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../FLV_Media_Player.exe  (3ad0f46dfbd0eda2012c7115a689a2f2)

1 / 68      (Adware)
http://dl.s0ftpzivrubajjui.net/n/.../Deer Hunter 2005.exe  (a3addff47bd700fa10bc9d362d3ce20f)

 
Latest 30 of 52 download URLs

The following 361 files have been seen to comunicate with dl.s0ftpzivrubajjui.net in live environments.

TCP » 54.72.9.51:80

 
Latest 20 of 372 files

URL:
http://dl.s0ftpzivrubajjui.net/

Google Analytics:
UA-48689684

Title:
“s0ftpzivrubajjui.net”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx

30 of 618 related domains