flv.hs4dmr.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain flv.hs4dmr.com is registered by proxy through GODADDY.COM, LLC and was originally registered in June of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Remove Malware from flv.hs4dmr.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Thursday, June 20, 2013

Expires date:
Monday, June 20, 2016

Updated date:
Sunday, June 21, 2015

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.BechiroSL.F, PUP.Solimba.FIRSERIA.Bundler (M), PUP.Solimba.Bechiro.Bundler (M), PUP.Adknowledge.SOFTWAREINSTALLER.Installer (M), PUP.Air Software.AirSoftware.Bundler (M), PUP.Downloadius.Downloadious.Installer (M), PUP.Softpulse.PluginUpdate.Bundler (M)
95.92%

AVG
Adware Skodna.Generic.AMG, Adware AdPlugin, Rollnon
73.47%

Malwarebytes
PUP.Optional.Solimba, PUP.Optional.OptimumInstaller.A, PUP.Optional.BundleInstaller.A
71.43%

Dr.Web
Adware.Downware.1302, Adware.Downware.2216, Adware.Downware.11360, infected with Trojan.DownLoad3.27029
71.43%

VIPRE Antivirus
DownloadMR, Threat.4778314, Ignition Installer, Threat.4782985, Threat.4782980
71.43%

K7 Gateway Antivirus
Unwanted-Program
69.39%

K7 AntiVirus
Trojan , Unwanted-Program
69.39%

Sophos
PUA 'Solimba Installer', iBryte Optimum Installer, Mal/Frethog-B
69.39%

Comodo Security
Application.Win32.Solimba.L, ApplicUnwnt, Packed.Win32.MUPX.Gen
69.39%

Avira AntiVirus
APPL/Solimba.Gen, Adware/iBryte.qoemnl, PUA/Solimba.Gen, TR/ATRAPS.Gen
69.39%

NANO AntiVirus
Trojan.Win32.Generic.cskuge, Trojan.Win32.OptInstall.czmuci, Trojan.Win32.DownLoad3.daevxj, Trojan.Win32.Vittalia.dqfrig
69.39%

Panda Antivirus
Adware/Firseria, Trj/Genetic.gen, Adware/AirInstaller
69.39%

Agnitum Outpost
PUA.Solimba, PUA.Downloader
67.35%

Vba32 AntiVirus
TScope.Trojan.MSIL, Downloader.Agent.bkfx, Signed-Downware.Morstar.BechiroSL
67.35%

Rising Antivirus
PE:PUF.FirseriaInstaller@CV!1.5C42, PE:Malware.iBryte!6.14B5
67.35%

The domain flv.hs4dmr.com has been seen to resolve to the following 46 IP addresses.

ec2-54-208-254-134.compute-1.amazonaws.com
February 12, 2016

ec2-52-73-156-129.compute-1.amazonaws.com
February 12, 2016

ec2-52-72-251-195.compute-1.amazonaws.com
February 3, 2016

ec2-52-72-181-246.compute-1.amazonaws.com
February 3, 2016

ec2-52-20-106-232.compute-1.amazonaws.com
January 27, 2016

ec2-54-172-73-48.compute-1.amazonaws.com
January 27, 2016

ec2-54-210-166-20.compute-1.amazonaws.com
January 3, 2016

ec2-52-7-138-198.compute-1.amazonaws.com
January 3, 2016

ec2-52-0-100-231.compute-1.amazonaws.com
December 19, 2015

ec2-54-172-168-97.compute-1.amazonaws.com
December 19, 2015

ec2-52-3-21-93.compute-1.amazonaws.com
December 19, 2015

ec2-52-7-53-84.compute-1.amazonaws.com
December 15, 2015

ec2-107-23-147-56.compute-1.amazonaws.com
December 15, 2015

ec2-52-22-175-167.compute-1.amazonaws.com
December 15, 2015

ec2-52-0-153-235.compute-1.amazonaws.com
December 7, 2015

ec2-52-20-249-17.compute-1.amazonaws.com
December 7, 2015

ec2-52-6-249-139.compute-1.amazonaws.com
December 7, 2015

ec2-54-174-196-254.compute-1.amazonaws.com
December 2, 2015

ec2-54-152-47-82.compute-1.amazonaws.com
December 2, 2015

ec2-52-20-252-132.compute-1.amazonaws.com
December 2, 2015

ec2-52-4-192-34.compute-1.amazonaws.com
November 25, 2015

ec2-107-23-109-144.compute-1.amazonaws.com
November 25, 2015

ec2-54-164-41-161.compute-1.amazonaws.com
November 25, 2015

ec2-52-2-106-76.compute-1.amazonaws.com
November 6, 2015

ec2-52-2-7-203.compute-1.amazonaws.com
November 6, 2015

ec2-54-175-187-52.compute-1.amazonaws.com
November 6, 2015

ec2-52-7-149-60.compute-1.amazonaws.com
August 12, 2015

ec2-54-86-172-158.compute-1.amazonaws.com
July 23, 2015

ec2-107-23-100-205.compute-1.amazonaws.com
July 23, 2015

ec2-54-173-193-7.compute-1.amazonaws.com
July 23, 2015

 
Showing 30 of 46 IP Addresses

File downloads found at URLs served by flv.hs4dmr.com.

 
Latest 30 of 75 download URLs

The following file have been seen to comunicate with flv.hs4dmr.com in live environments.

URL:
http://flv.hs4dmr.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx/1.7.9

Remove Malware from flv.hs4dmr.com - Powered by Reason Core Security