download.remobo.com

AWIT Systems

Domain Information

The domain download.remobo.com registered by AWIT Systems was initially registered in November of 2006 through GODADDY.COM, LLC. Currently this domain has been known to host various forms of malware. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Saturday, November 11, 2006

Expires date:
Friday, November 11, 2016

Updated date:
Wednesday, November 12, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Comodo Security
UnclassifiedMalware, Worm.Win32.Agent.BSM
100.00%

Reason Heuristics
Unnamed.Threat.19, Threat.Win.Reputation.IMP
100.00%

McAfee
Artemis!CBA5AC7F690D
50.00%

K7 AntiVirus
Trojan
50.00%

Norman
Suspicious_Gen4.FRRUK
50.00%

Trend Micro House Call
TROJ_GE.43717A41
50.00%

VIPRE Antivirus
Trojan.Win32.Generic
50.00%

ESET NOD32
Win32/3Proxy.NAF (variant)
50.00%

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
50.00%

Fortinet FortiGate
Riskware/3proxy
50.00%

Bkav FE
HW32.Packed
50.00%

The domain download.remobo.com has been seen to resolve to the following 2 IP addresses.

s3-1-w.amazonaws.com
October 28, 2015

s3-1-w.amazonaws.com
September 3, 2014

File downloads found at URLs served by download.remobo.com.

3 / 68      (Malware)
http://download.remobo.com/RemoboSetup-0.50.3.exe  (c9492f87652b9837c3a3ec09c784289d)

10 / 68    (Malware)
http://download.remobo.com/RemoboSetup-0.72.1-2.exe  (cba5ac7f690d12db4d30dfdca27ccb15)

The following 3 files have been seen to comunicate with download.remobo.com in live environments.

URL:
http://download.remobo.com/

Network:
Amazon Web Services (AWS)

Web server:
AmazonS3