tornnow.com

NameFind LLC

Domain Information

The domain tornnow.com registered by NameFind LLC was initially registered in August of 2014 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Sunday, August 03, 2014

Expires date:
Wednesday, August 03, 2016

Updated date:
Tuesday, April 05, 2016

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US

Scanner detections:
Detections  (89% detected)

Scan engine
Details
Detections

NANO AntiVirus
Trojan.Nsis.Yotoon.deckrr, Trojan.Win32.MLW.doamla
85.19%

Sophos
Generic PUA DC, CoolMirage
77.78%

Reason Heuristics
PUP.VASSANAKONGSOONGNERN.n, PUP.VASSANAKONGSOONGNERN.FF, PUP.VASSANAKONGSOONGNERN.i, PUP.VASSANAKONGSOONGNERN.?, PUP.VASSANAKONGSOONGNERN.k, PUP.CoolMirage.VASSANAK.Installer (M)
77.78%

Dr.Web
Adware.Yontoo.54, Adware.Downware.8319, Detection.Undefined
74.07%

K7 AntiVirus
Adware
74.07%

AVG
Generic, Could be an adware MultiBundle
74.07%

VIPRE Antivirus
CoolMirage Ltd
70.37%

Avira AntiVirus
ADWARE/Adware.Gen, APPL/Downloader.Gen
66.67%

ESET NOD32
Win32/Adware.1ClickDownload.AJ, NSIS/TrojanDropper.Agent.CB, Win32/Adware.1ClickDownload.AY
66.67%

Qihoo 360 Security
Win32/Virus.Adware.47b, Win32/Virus.Downloader.e28
51.85%

McAfee
Artemis!FA761D2EC0BE, Artemis!E5316666B523, Artemis!D3626BEA51AB, Artemis!E5639A81F7BF, Artemis!0B395897DA2E, Artemis!D47A8842051B, Artemis!61FEAB187343, Artemis!692F7346029A, Artemis!C175864F28C5
48.15%

AhnLab V3 Security
Win-PUP/CrossRider, PUP/Win32.Helper
48.15%

Kaspersky
not-a-virus:AdWare.NSIS.Yontoo, not-a-virus:Downloader.Win32.TornTV
44.44%

Baidu Antivirus
Adware.NSIS.Yontoo, Adware.Win32.1ClickDownload, Hacktool.Win32.TornTV
44.44%

Trend Micro House Call
Suspicious_GEN.F47V1225, ADW_YONTOO, Suspicious_GEN.F47V0124, Suspicious_GEN.F47V0128, Suspicious_GEN.F47V0202, Suspici.EDD0D2A5
33.33%

The domain tornnow.com has been seen to resolve to the following 9 IP addresses.

April 13, 2016

February 6, 2016

ip-50-63-202-57.ip.secureserver.net
August 12, 2015

ec2-54-246-120-161.eu-west-1.compute.amazonaws.com
June 26, 2015

ec2-176-34-107-151.eu-west-1.compute.amazonaws.com
June 18, 2015

ec2-54-217-233-226.eu-west-1.compute.amazonaws.com
May 4, 2015

ec2-54-228-201-246.eu-west-1.compute.amazonaws.com
May 4, 2015

ec2-184-169-157-32.us-west-1.compute.amazonaws.com
January 13, 2015

ec2-50-18-168-176.us-west-1.compute.amazonaws.com
January 12, 2015

File downloads found at URLs served by tornnow.com.

12 / 68    (Adware)
http://tornnow.com/.../unibomber2_iso.php?pub=ap1015106&file=Frnfba 2 &name=Frnfba 2 &fall=1  (microsoft_office_2010_professional_plus_x86_x64_en_us_final_007_[ctrg].exe)

 
Latest 30 of 65 download URLs

The following 185 files have been seen to comunicate with tornnow.com in live environments.

 
Latest 20 of 186 files

URL:
http://tornnow.com/

Title:
“tornnow.com”

Web server:
Apache

Facebook:
Shares:  2

Statistics above are for the previous month of September 2018.