torntv-tv.info

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain torntv-tv.info is registered by proxy through GoDaddy.com, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Registrar:
GoDaddy.com, LLC

Server location:
Dublin City, Ireland (IE)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (95% detected)

Scan engine
Details
Detections

NANO AntiVirus
Trojan.Nsis.Yotoon.deckrr
94.44%

ESET NOD32
Win32/Adware.1ClickDownload.AJ
94.44%

Reason Heuristics
PUP.VASSANAKONGSOONGNERN.?, PUP.VASSANAKONGSOONGNERN.b, PUP.VASSANAKONGSOONGNERN.i, PUP.VASSANAKONGSOONGNERN.Z, PUP.VASSANAKONGSOONGNERN.Q, PUP.ThitawanChotiga.Installer (M)
94.44%

K7 AntiVirus
Adware
88.89%

Dr.Web
Adware.Downware.8319, Adware.Yontoo.54
88.89%

Sophos
CoolMirage
88.89%

AVG
Generic
88.89%

VIPRE Antivirus
Trojan.Win32.Generic, CoolMirage Ltd
83.33%

Avira AntiVirus
ADWARE/Adware.Gen
77.78%

Kaspersky
not-a-virus:AdWare.NSIS.Yontoo
77.78%

McAfee
Artemis!B78CD7700F3C, Artemis!17F6A61551BF, Artemis!568603FCF46B, Artemis!B64DD60B7423, Artemis!ECC5C14DFA49, Artemis!1B362BD9776C, Artemis!A3B2C191A23F, Artemis!F68334F9A43B, Artemis!56CF38819759, Artemis!5E782DF4A432
66.67%

Trend Micro House Call
Suspicious_GEN.F47V1115, Suspicious_GEN.F47V1210, Suspicious_GEN.F47V1207, Suspicious_GEN.F47V1214, Suspicious_GEN.F47V1215
50.00%

avast!
NSIS:Adware-QL [PUP], Win32:Adware-gen [Adw]
22.22%

Qihoo 360 Security
Win32/Virus.Adware.47b, HEUR/QVM42.0.Malware.Gen, Malware.QVM06.Gen
22.22%

Malwarebytes
PUP.Optional.Downloader, Adware.Agent
16.67%

The domain torntv-tv.info has been seen to resolve to the following 5 IP addresses.

September 4, 2016

ec2-54-217-233-226.eu-west-1.compute.amazonaws.com
May 3, 2015

ec2-54-228-201-246.eu-west-1.compute.amazonaws.com
May 3, 2015

ec2-50-18-168-176.us-west-1.compute.amazonaws.com
January 9, 2015

ec2-184-169-157-32.us-west-1.compute.amazonaws.com
November 29, 2014

File downloads found at URLs served by torntv-tv.info.

5 / 68      (PUP)
http://torntv-tv.info/common/unibomber2.php?pub=p0_tload&file=uggc://jjj.gbeeragqbjaybnqf.arg&name=ovt ureb 6&fall=1  ([isohunt]_warcraft_iii_reign_of_chaos,_the_frozen_throne___update_patch_war3tft_122a_english,_cdkey.)

14 / 68    (Adware)

 
Latest 30 of 36 download URLs

The following 3 files have been seen to comunicate with torntv-tv.info in live environments.