s.premium-apps.net

PERFECT PRIVACY, LLC  (Proxy Registrant)

Domain Information

The domain s.premium-apps.net is registered by proxy through Network Solutions, LLC and was originally registered in January of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Cleveland, Ohio within the United States which resides on the Highwinds Network Group, Inc. network.
Registrar:
Network Solutions, LLC

Server location:
Ohio, United States (US)

Create date:
Monday, January 06, 2014

Expires date:
Friday, January 06, 2017

Updated date:
Saturday, November 07, 2015

ASN:
AS12989 HWNG Eweka Internet Services B.V.

Root domain:

Scanner detections:
Detections  (88% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.LionSeaSoftwarecoltd.F, PUP.Installer.IgnitionInstaller.F, PUP.Installer.SecureDownload.J, PUP.OptimumInstaller.Bundler.Installer.Meta (M), PUP.Installer.DigitalPluginSl.F, PUP.Adknowledge.FileMonarch.Bundler (M), PUP.Softpulse.DIGITALP.Bundler (M), PUP.InstallCore.RES (M), PUP.Installa.Installer (M), PUP.Adknowledge.Fileange.Bundler (M), PUP.Outbrowse.Bundler (M), PUP.Softpulse.DigitalP.Bundler (M), PUP.SoftPulse.YumonSys.Installer (M), PUP.Outbrowse.OTOPIASo.Bundler (M), PUP.Softpulse.DIGITALP.Installer (M), PUP.Adknowledge (M)
93.55%

VIPRE Antivirus
Ignition Installer, Threat.4783235, Optimum Installer, Trojan.Win32.Generic
45.16%

Trend Micro House Call
TROJ_GEN.F47V0907, TROJ_GEN.F47V0214, TROJ_GEN.F47V0114, TROJ_GEN.F47V0403, TROJ_GEN.F47V0227, TROJ_GEN.F47V0110, TROJ_GEN.F47V0430, TROJ_GEN.F47V0506, TROJ_GEN.F47V0523
41.94%

Dr.Web
Adware.Downware.2039, Trojan.Click3.3888, Trojan.DownLoader11.30629, Adware.Downware.4908
41.94%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious.A, Artemis!DE1E6C268131, SoftPulse, Artemis!C867A8E42B17
38.71%

ESET NOD32
MSIL/Verti (variant), Win32/SoftPulse (variant), Win32/OutBrowse
25.81%

Malwarebytes
PUP.Optional.PremiumApps.A, PUP.Optional.OptimunInstaller, PUP.Optional.OutBrowse
22.58%

Antiy Labs AVL
Trojan/Win32.IRCbot, GrayWare[AdWare:not-a-virus]/Win32.Agent, Trojan/Win32.Badur
19.35%

McAfee
Artemis!4DC7D10FB20C, Artemis!11BE50869125, Artemis!DE1E6C268131, Program.SoftPulse, Trojan.Artemis!46F8749DEF37
19.35%

F-Secure
Gen:Variant.Symmi.37960, Adware.IBryte.AF, Adware.Agent.OBB
9.68%

Agnitum Outpost
Riskware.Agent, Trojan.Agent
9.68%

avast!
Win32:SoftPulse-V [PUP], Win32:PUP-gen [PUP], Win32:Adware-gen [Adw]
9.68%

Avira AntiVirus
TR/Dropper.Gen, Adware/iBryte.bxoh, APPL/Downloader.Gen
9.68%

Sophos
SoftPulse, iBryte Premium Installer, Generic PUA IN
9.68%

G Data
Win32.Adware.Softpulse, Adware.IBryte.AF, Adware.Agent.OBB
9.68%

The domain s.premium-apps.net has been seen to resolve to the following 191 IP addresses.

server-54-230-193-39.iad53.r.cloudfront.net
September 14, 2016

server-54-230-193-34.iad53.r.cloudfront.net
September 14, 2016

server-54-230-193-241.iad53.r.cloudfront.net
September 14, 2016

server-54-230-193-219.iad53.r.cloudfront.net
September 14, 2016

server-54-230-193-168.iad53.r.cloudfront.net
September 14, 2016

server-54-230-193-118.iad53.r.cloudfront.net
September 14, 2016

server-54-230-193-88.iad53.r.cloudfront.net
September 14, 2016

server-54-230-193-80.iad53.r.cloudfront.net
September 14, 2016

server-52-84-125-94.iad16.r.cloudfront.net
August 19, 2016

server-52-84-125-14.iad16.r.cloudfront.net
August 19, 2016

server-52-84-125-251.iad16.r.cloudfront.net
August 19, 2016

server-52-84-125-245.iad16.r.cloudfront.net
August 19, 2016

server-52-84-125-239.iad16.r.cloudfront.net
August 19, 2016

server-52-84-125-219.iad16.r.cloudfront.net
August 19, 2016

server-52-84-125-168.iad16.r.cloudfront.net
August 19, 2016

server-52-85-131-227.iad53.r.cloudfront.net
July 13, 2016

server-52-85-131-214.iad53.r.cloudfront.net
July 13, 2016

server-52-85-131-162.iad53.r.cloudfront.net
July 13, 2016

server-52-85-131-132.iad53.r.cloudfront.net
July 13, 2016

server-52-85-131-73.iad53.r.cloudfront.net
July 13, 2016

server-52-85-131-50.iad53.r.cloudfront.net
July 13, 2016

server-52-85-131-242.iad53.r.cloudfront.net
July 13, 2016

server-52-85-131-235.iad53.r.cloudfront.net
July 13, 2016

server-54-192-19-192.iad12.r.cloudfront.net
July 8, 2016

server-54-192-19-182.iad12.r.cloudfront.net
July 8, 2016

server-54-192-19-146.iad12.r.cloudfront.net
July 8, 2016

server-54-192-19-134.iad12.r.cloudfront.net
July 8, 2016

server-54-192-19-28.iad12.r.cloudfront.net
July 8, 2016

server-54-192-19-24.iad12.r.cloudfront.net
July 8, 2016

server-54-192-19-17.iad12.r.cloudfront.net
July 8, 2016

 
Showing 30 of 191 IP Addresses

File downloads found at URLs served by s.premium-apps.net.

1 / 68      (Adware)
http://s.premium-apps.net/stub/.../setup.exe  (7a410b359a91d7e5f201de2592e75dc9)

The following 2192 files have been seen to comunicate with s.premium-apps.net in live environments.

 
Latest 20 of 2,401 files

URL:
http://s.premium-apps.net/

Web server:
AmazonS3