s.premium-apps.net

PERFECT PRIVACY, LLC  (Proxy Registrant)

Domain Information

The domain s.premium-apps.net is registered by proxy through Network Solutions, LLC and was originally registered in January of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Cleveland, Ohio within the United States which resides on the Highwinds Network Group, Inc. network.
Remove Malware from s.premium-apps.net - Powered by Reason Core Security
Registrar:
Network Solutions, LLC

Server location:
Ohio, United States (US)

Create date:
Monday, January 06, 2014

Expires date:
Friday, January 06, 2017

Updated date:
Saturday, November 07, 2015

ASN:
AS12989 HWNG Eweka Internet Services B.V.

Root domain:

Scanner detections:
Detections  (88% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.LionSeaSoftwarecoltd.F, PUP.Installer.IgnitionInstaller.F, PUP.OptimumInstaller.Bundler.Installer.Meta (M), PUP.Installer.DigitalPluginSl.F, PUP.Adknowledge.FileMonarch.Bundler (M)
93.75%

Trend Micro House Call
TROJ_GEN.F47V0907, TROJ_GEN.F47V0214, TROJ_GEN.F47V0114, TROJ_GEN.F47V0403, TROJ_GEN.F47V0227, TROJ_GEN.F47V0110, TROJ_GEN.F47V0430, TROJ_GEN.F47V0506, TROJ_GEN.F47V0523
81.25%

VIPRE Antivirus
Ignition Installer, Threat.4783235, Optimum Installer
81.25%

Dr.Web
Adware.Downware.2039, Trojan.Click3.3888, Trojan.DownLoader11.30629
75.00%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious.A, Artemis!DE1E6C268131, SoftPulse, Artemis!C867A8E42B17
75.00%

ESET NOD32
MSIL/Verti (variant), Win32/SoftPulse (variant)
43.75%

Malwarebytes
PUP.Optional.PremiumApps.A, PUP.Optional.OptimunInstaller
37.50%

Antiy Labs AVL
Trojan/Win32.IRCbot, GrayWare[AdWare:not-a-virus]/Win32.Agent, Trojan/Win32.Badur
37.50%

McAfee
Artemis!4DC7D10FB20C, Artemis!11BE50869125, Artemis!DE1E6C268131, Program.SoftPulse, Trojan.Artemis!46F8749DEF37
37.50%

Agnitum Outpost
Riskware.Agent, Trojan.Agent
18.75%

herdProtect (fuzzy)
a variant of 3ea773ad0bbe7409a6efc9739b54514a9132e1a7, a variant of 1101f492613cf7198ae3652ec68d4752a235af80
12.50%

avast!
Win32:SoftPulse-V [PUP], Win32:PUP-gen [PUP]
12.50%

Avira AntiVirus
TR/Dropper.Gen, Adware/iBryte.bxoh
12.50%

Kaspersky
not-a-virus:AdWare.Win32.Agent, not-a-virus:AdWare.Win32.iBryte
12.50%

K7 AntiVirus
Unwanted-Program
12.50%

The domain s.premium-apps.net has been seen to resolve to the following 88 IP addresses.

server-54-230-102-250.iad2.r.cloudfront.net
February 14, 2016

server-54-230-102-212.iad2.r.cloudfront.net
February 14, 2016

server-54-230-102-205.iad2.r.cloudfront.net
February 14, 2016

server-54-230-102-195.iad2.r.cloudfront.net
February 14, 2016

server-54-230-102-185.iad2.r.cloudfront.net
February 14, 2016

server-54-230-102-141.iad2.r.cloudfront.net
February 14, 2016

server-54-230-102-107.iad2.r.cloudfront.net
February 14, 2016

server-54-230-102-33.iad2.r.cloudfront.net
February 14, 2016

server-54-192-195-167.iad53.r.cloudfront.net
February 7, 2016

server-54-192-195-158.iad53.r.cloudfront.net
February 7, 2016

server-54-192-195-155.iad53.r.cloudfront.net
February 7, 2016

server-54-192-195-138.iad53.r.cloudfront.net
February 7, 2016

server-54-192-195-124.iad53.r.cloudfront.net
February 7, 2016

server-54-192-195-106.iad53.r.cloudfront.net
February 7, 2016

server-54-192-195-15.iad53.r.cloudfront.net
February 7, 2016

server-54-192-195-219.iad53.r.cloudfront.net
February 7, 2016

server-54-192-54-173.jfk6.r.cloudfront.net
May 5, 2015

server-54-192-54-198.jfk6.r.cloudfront.net
May 5, 2015

server-54-230-53-82.jfk6.r.cloudfront.net
May 5, 2015

server-54-192-55-161.jfk6.r.cloudfront.net
May 5, 2015

server-54-192-54-193.jfk6.r.cloudfront.net
May 5, 2015

server-54-230-55-223.jfk6.r.cloudfront.net
May 5, 2015

server-54-192-54-195.jfk6.r.cloudfront.net
May 5, 2015

server-54-230-52-91.jfk6.r.cloudfront.net
May 5, 2015

server-54-230-103-187.iad2.r.cloudfront.net
September 5, 2014

server-54-230-103-136.iad2.r.cloudfront.net
September 5, 2014

server-54-230-102-251.iad2.r.cloudfront.net
September 5, 2014

server-54-230-102-160.iad2.r.cloudfront.net
September 5, 2014

server-54-230-100-169.iad2.r.cloudfront.net
September 5, 2014

server-54-230-100-39.iad2.r.cloudfront.net
September 5, 2014

 
Showing 30 of 88 IP Addresses

File downloads found at URLs served by s.premium-apps.net.

45 / 68    (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (61129a7cb0a6f628443901b91529c4ab)

6 / 68      (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (92eca2bedeb946494021079a0f918a3d)

0 / 68
http://s.premium-apps.net/stub/.../setup.exe  (7ccdb06729e2731af9d0dfbd86b437de)

7 / 68      (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (de1e6c268131e6d3dcd690973ee55894)

1 / 68
http://s.premium-apps.net/stub/.../setup.exe  (9a3112f0fbd1069568c077f1a381aa7b)

20 / 68    (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (04ca4161ee4c8ed14dd95c2ba152a350)

5 / 68      (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (d77ede23bad5f3e87ee892ab3554b1ba)

6 / 68      (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (e613c923a93e74fca09603f07707ec75)

1 / 68      (PUP)
http://s.premium-apps.net/stub/.../setup.exe  (4fbbc33827a041299cd6fd3a7bd8c91b)

1 / 68      (PUP)
http://s.premium-apps.net/stub/.../setup.exe  (52cd6d3b61719f7e0735a0c930867f2b)

8 / 68      (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (11be5086912595baf46f4224dba15738)

6 / 68      (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (96bdaa70672d3bcef8bbd7ecdfb6828d)

7 / 68      (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (4dc7d10fb20c42c05e41f809431594bd)

8 / 68      (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (d0746e5cb267723e4c9bbaed4a854348)

7 / 68      (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (2650a1b9f31d5479196d9a2184ad2840)

7 / 68      (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (5a74943fdc8a3cbfb966320d61efb890)

7 / 68      (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (4b2b476c33357b553867fe0e7586adf1)

The following 1682 files have been seen to comunicate with s.premium-apps.net in live environments.

 
Latest 20 of 1,708 files

URL:
http://s.premium-apps.net/

Web server:
AmazonS3

Remove Malware from s.premium-apps.net - Powered by Reason Core Security