dw.com.com

WHOIS PRIVACY PROTECTION SERVICE, INC.  (Proxy Registrant)

Domain Information

The domain dw.com.com is registered by proxy through ENOM, INC. and was originally registered in April of 1995. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Remove Malware from dw.com.com - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
Oregon, United States (US)

Create date:
Thursday, April 13, 1995

Expires date:
Friday, April 14, 2023

Updated date:
Friday, January 17, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.WebInstall.P, PUP.Installer.WebInstall.S, PUP.Installer.WebInstall.DD, PUP.Installer.WebInstall.V, PUP.Installer.WebInstall.O, PUP.Installer.WebInstall.L, PUP.Installer.WebInstall.M, PUP.Installer.CBS, Threat.CBS.Bundler, PUP.WebInstall.Installer (M), PUP.CBS.WebInstall.Installer (M)
89.80%

VIPRE Antivirus
Threat.4782786, WebInstall, Threat.4150696
38.78%

Dr.Web
Adware.Downware.1159, Adware.Downware.398, Adware.Downware.922, Trojan.Vittalia.81
34.69%

NANO AntiVirus
Riskware.Win32.Downware.crgjbr, Trojan.Win32.Downware.crgjbr, Riskware.Nsis.Downware.dlgjls, Trojan.Win32.Agent.dtlegd
30.61%

avast!
Adware-BGE [PUP]
28.57%

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application
28.57%

Agnitum Outpost
PUA.Downware
24.49%

K7 AntiVirus
Trojan , Dialer , Adware
16.33%

K7 Gateway Antivirus
Trojan , Dialer , Adware
16.33%

herdProtect (fuzzy)
a variant of 713ef952ac6a358c8abfa39550aa98592ec79d47, a variant of e68d6c794ef391e559249b53137fc4227a7854ac, a variant of ad7f1c2b54695465befc71318f5c395b08b8e57f
12.24%

ESET NOD32
Win32/DownloadAdmin, Win32/DownloadAdmin.G potentially unwanted
10.20%

Trend Micro House Call
TROJ_GEN.F47V0807, TROJ_GEN.F47V0419, Suspicious_GEN.F47V0412
8.16%

Clam AntiVirus
Win.Adware.Agent-6650
6.12%

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
6.12%

Emsisoft Anti-Malware
Riskware.Win32.DownloadAdmin.AMN, Gen:Variant.Strictor.89231
6.12%

The domain dw.com.com has been seen to resolve to the following 6 IP addresses.

ec2-54-201-82-69.us-west-2.compute.amazonaws.com
November 10, 2014

ec2-54-68-81-199.us-west-2.compute.amazonaws.com
September 18, 2014

ec2-54-183-116-245.us-west-1.compute.amazonaws.com
August 1, 2014

ec2-54-183-52-48.us-west-1.compute.amazonaws.com
July 7, 2014

ec2-50-18-112-106.us-west-1.compute.amazonaws.com
June 9, 2014

January 8, 2014

File downloads found at URLs served by dw.com.com.

 
Latest 30 of 61 download URLs

URL:
http://dw.com.com/

Google Analytics:
UA-51822516

Title:
“.xyz Domain Names | Join Generation XYZ”

Description:
“.xyz is for every website, everywhere.™ We offer the most flexible and affordable domain names to create choice for the next generation of internet users.”

Network:
Amazon Web Services (AWS), running an EC2 instance

SSL certificate subject:
CN=*.com.com, OU=Domain Control Validated - RapidSSL(R), OU=See www.rapidssl.com/resources/cps (c)15, OU=GT08503494

SSL certificate issuer:
CN=RapidSSL SHA256 CA - G3, O=GeoTrust Inc., C=US

Web server:
Apache

Facebook:
Likes:  9
Shares:  2

Compete.com:
US visitors:  12,759

Statistics are for the previous month.

Remove Malware from dw.com.com - Powered by Reason Core Security