fastwinnermyall.ru

Private Person  (Proxy Registrant)

Domain Information

The domain fastwinnermyall.ru is registered by proxy through R01-REG-RIPN and was originally registered in August of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
R01-REG-RIPN

Server location:
Oregon, United States (US)

Create date:
Wednesday, August 21, 2013

Expires date:
Thursday, August 21, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.KirilKlimko.G, PUP.WebPick.PavelKRASNOV.Bundler (M), PUP.WebPick.BorisVladimirovichBOBOVSKY (M), PUP.WebPick.PavelKRASNOV (M), PUP.WebPick.BorisVladimirovichBOBOVSKY.Bundler (M), PUP.WebPick.PavelKRA.Bundler (M), PUP.WebPick.BorisVla.Bundler (M)
100.00%

MicroWorld eScan
Gen:Variant.Adware.Dropper.101
2.44%

McAfee
PUP-FID!0D45DA2D895A
2.44%

Agnitum Outpost
PUA.MultiPlug
2.44%

Bitdefender
Gen:Variant.Adware.Dropper.101
2.44%

NANO AntiVirus
Trojan.Win32.Crossrider.cvopfn
2.44%

Lavasoft Ad-Aware
Gen:Variant.Adware.Dropper.101
2.44%

Sophos
MultiPlug
2.44%

Comodo Security
Application.Win32.Multiplug.R
2.44%

F-Secure
Gen:Variant.Adware.Dropper.101
2.44%

Dr.Web
Trojan.Crossrider.5139
2.44%

VIPRE Antivirus
JustPlugIt
2.44%

Avira AntiVirus
ADWARE/Adware.Gen7
2.44%

Emsisoft Anti-Malware
Gen:Variant.Adware.Dropper.101
2.44%

G Data
Gen:Variant.Adware.Dropper.101
2.44%

The domain fastwinnermyall.ru has been seen to resolve to the following IP address.

ec2-54-201-91-18.us-west-2.compute.amazonaws.com
April 4, 2014

File downloads found at URLs served by fastwinnermyall.ru.

 
Latest 30 of 41 download URLs

The following 3 files have been seen to comunicate with fastwinnermyall.ru in live environments.