storagemen.net

Igal Geterman

Domain Information

The domain storagemen.net registered by Igal Geterman was initially registered in August of 2014 through NAME.COM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
NAME.COM, INC.

Server location:
Oregon, United States (US)

Create date:
Tuesday, August 19, 2014

Expires date:
Wednesday, August 19, 2015

Updated date:
Tuesday, August 26, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (70% detected)

Scan engine
Details
Detections

Dr.Web
Trojan.Packed.24060, Trojan.DownLoader11.38525, Trojan.DownLoader11.38297, Trojan.WebPick.2910, Trojan.DownLoader11.38327, Trojan.DownLoader11.38313, Trojan.Crossrider.36808, Trojan.Crossrider.36731
92.59%

ESET NOD32
Win32/AdWare.MultiPlug.CN application, Win32/AdWare.MultiPlug.CT application, Win32/Adware.MultiPlug.HV application
92.59%

avast!
JS:Redirector-BWK [Trj], Win32:MultiPlug-JU [PUP], Win32:Agent-AUVV [Trj], Win32:FakeDownload-G [PUP], Win32:Agent-AYLT [PUP]
88.89%

AVG
Adware Generic_r.VD
85.19%

McAfee
MultiPlug-FRO, Program.MultiPlug-FRO, Program.MultiPlug-FRE
85.19%

Emsisoft Anti-Malware
Gen:Variant.Kazy.477538, Trojan.Agent.BGEG, Adware.Mplug.CR, Gen:Variant.Adware.MPlug.16, Application.Bundler.FP, Application.Downloader.UI
85.19%

Norman
Trojan.Agent.BGEG, Adware.Mplug.CR, Gen:Variant.Adware.MPlug.16, Application.Bundler.FP, Application.Downloader.UI, Gen:Variant.Adware.MPlug.10
81.48%

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug, HEUR:Trojan.Win32.Generic, not-a-virus:HEUR:AdWare.Win32.MultiPlug
74.07%

Microsoft Security Essentials
Threat.Undefined
48.15%

VIPRE Antivirus
Threat.5085665, Threat.5180739
40.74%

F-Secure
Trojan.Agent.BGEG, Adware.Mplug.CR, Gen:Variant.Adware.MPlug
37.04%

Sophos
PUA 'MultiPlug' (of type Adware)
37.04%

NANO AntiVirus
Riskware.Win32.MultiPlug.dfjscb, Riskware.Win32.MultiPlug.dgysyh
25.93%

Vba32 AntiVirus
SScope.Adware.MultiPlug
25.93%

Avira AntiVirus
ADWARE/MultiPlug.Gen7
22.22%

The domain storagemen.net has been seen to resolve to the following 2 IP addresses.

ec2-54-68-56-152.us-west-2.compute.amazonaws.com
May 3, 2015

ec2-54-68-145-207.us-west-2.compute.amazonaws.com
October 24, 2014

File downloads found at URLs served by storagemen.net.

2 / 68      (PUP)
http://storagemen.net/.../Download.exe  (d8d32589f00eb544b7e95cfc03d8b7cb)

0 / 68
http://storagemen.net/.../f.exe  (82b61619848322d9dfba7e7d8667267f)

0 / 68
http://storagemen.net/.../Retrica Download.exe  (ab6e649f003d076a0c9d50212ec7d518)

9 / 68      (PUP)

9 / 68      (PUP)
http://storagemen.net/.../Hermanos - 1x01.exe  (eac2ef6993c7141fd419df9a0ad644a3)

25 / 68    (PUP)
http://storagemen.net/.../Game of Thrones.exe  (5e183384dae33f5ff5738f10a6e6f84b)

9 / 68      (PUP)

0 / 68
http://storagemen.net/.../com.nucleoid.android.l.apk.exe  (ae9926db6ad49e8c5ebe24e5123f00cb)

URL:
http://storagemen.net/

Google Analytics:
UA-19438610

Title:
“PC Experts :: Home”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx