dl3.urbanmusichq.se

EXHEHH6557-58743

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
1 Api GmbH

Server location:
Oregon, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer.Z, Adware.WebPick.Installer.J, Adware.WebPick.Installer.Y
100.00%

McAfee
PUP-FHQ!DDB3DE2D761F, PUP-FHQ!B02C03E45D5D
100.00%

Malwarebytes
PUP.Optional.Installrex, PUP.Optional.InstalleRex
100.00%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696
100.00%

K7 AntiVirus
Unwanted-Program , Trojan
100.00%

NANO AntiVirus
Riskware.Win32.InfoLeak.cvgqot
100.00%

avast!
Win32:InstalleRex-BI [PUP]
100.00%

Kaspersky
Trojan.Win32.AntiFW
100.00%

Agnitum Outpost
Trojan.AntiFW
100.00%

Sophos
InstallRex
100.00%

Comodo Security
Application.Win32.InstalleRex.KG
100.00%

Dr.Web
Trojan.WebPick.29
100.00%

Avira AntiVirus
TR/AntiFW.b.89, TR/AntiFW.b.86
100.00%

G Data
Win32.Application.EZDownloader, Application.Generic.623310, Application.Generic.621702
100.00%

Vba32 AntiVirus
Downloader.AdLoad, Downware.TSU
100.00%

The domain dl3.urbanmusichq.se has been seen to resolve to the following 3 IP addresses.

May 21, 2014

May 21, 2014

ec2-54-200-139-91.us-west-2.compute.amazonaws.com
May 1, 2014

File downloads found at URLs served by dl3.urbanmusichq.se.

28 / 68    (Adware)

28 / 68    (Adware)
http://dl3.urbanmusichq.se/.../Example –.exe  (b02c03e45d5d27961899bbd1c8a8c9aa)

20 / 68    (Adware)

URL:
http://dl3.urbanmusichq.se/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
cloudflare-nginx