gbuzz.rewardzone.sonscarecrow.biz

Fundacion Private Whois  (Proxy Registrant)

Domain Information

The domain gbuzz.rewardzone.sonscarecrow.biz is registered by proxy through INTERNET.BS CORP. and was originally registered in September of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
INTERNET.BS CORP.

Server location:
Virginia, United States (US)

Create date:
Monday, September 1, 2014

Expires date:
Monday, August 31, 2015

Updated date:
Monday, September 1, 2014

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.PluginUpdateSL.O
100.00%

Emsisoft Anti-Malware
Application.Bundler.DomaIQ.T
100.00%

Dr.Web
Trojan.DownLoader11.30734
100.00%

avast!
Win32:GenMalicious-NP [PUP]
100.00%

AVG
Win.Threat.High
100.00%

VIPRE Antivirus
Threat.4783235
100.00%

MicroWorld eScan
Application.Bundler.DomaIQ.T
100.00%

McAfee
SoftPulse
100.00%

Malwarebytes
PUP.Optional.DomaIQ
100.00%

K7 AntiVirus
Unwanted-Program
100.00%

NANO AntiVirus
Riskware.Win32.SoftPulse.deniau
100.00%

Norman
Malware
100.00%

Bitdefender
Application.Bundler.DomaIQ.T
100.00%

Agnitum Outpost
Riskware.Agent
100.00%

Lavasoft Ad-Aware
Application.Bundler.DomaIQ.T
100.00%

The domain gbuzz.rewardzone.sonscarecrow.biz has been seen to resolve to the following 2 IP addresses.

ec2-184-73-247-179.compute-1.amazonaws.com
September 10, 2014

208.43.10.6-static.reverse.softlayer.com
September 9, 2014

File downloads found at URLs served by gbuzz.rewardzone.sonscarecrow.biz.

URL:
http://gbuzz.rewardzone.sonscarecrow.biz/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Microsoft-IIS/7.5