tr.im

Domain Information

Remove Malware from tr.im - Powered by Reason Core Security
Server location:
Virginia, United States (US)

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Scanner detections:
Detections  (80% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.OOOSoftMedia.R, PUP.Installer.iDatixCorporation.U, Threat.InstallMonster.DIREKTTUR
75.00%

avast!
Win32:Adware-gen [Adw], Win32:Malware-gen
75.00%

VIPRE Antivirus
Threat.4150696, Threat.5064197
50.00%

Dr.Web
Adware.Downware.1666, Trojan.InstallMonster
50.00%

Sophos
WebAlta Toolbar, PUA 'Install Monster'
50.00%

Avira AntiVirus
ADWARE/Adware.Gen, ADWARE/InstaMon.enif
50.00%

ESET NOD32
Win32/AdWare.Toolbar.Webalta.GN, Win32/InstallMonstr.JM potentially unwanted (variant)
50.00%

AVG
Win.Threat.Medium, Generic
50.00%

Agnitum Outpost
PUA.Toolbar
25.00%

Comodo Security
Application.Win32.Agent.WEFX
25.00%

Antiy Labs AVL
Trojan/Win32.TSGeneric
25.00%

Vba32 AntiVirus
Downware.iDatix.gen
25.00%

herdProtect (fuzzy)
a variant of 9e5c50b565bcfb7464ae844effb11a5bce3a73b5
25.00%

Bkav FE
W32.HfsAdware
25.00%

K7 AntiVirus
Unwanted-Program
25.00%

The domain tr.im has been seen to resolve to the following 3 IP addresses.

ec2-54-165-60-202.compute-1.amazonaws.com
May 21, 2015

ec2-54-243-183-205.compute-1.amazonaws.com
August 12, 2014

ec2-54-243-112-104.compute-1.amazonaws.com
June 5, 2014

File downloads found at URLs served by tr.im.

0 / 68
https://tr.im/startdownloadmovieidpinlardoctypehdmoviejiku  (GraboidVideoInstaller-5.2.1.0.exe)

0 / 68
https://tr.im/startwatchingmovieidpintumiaisagolalkumra  (GraboidVideoInstaller-5.2.1.0.exe)

0 / 68
https://tr.im/DirectFreeDownloadPC  (GraboidVideoInstaller-5.2.1.0.exe)

0 / 68
https://tr.im/watchonlinei  (GraboidVideoInstaller-5.2.1.0.exe)

14 / 68    (Malware)
http://tr.im/.../IMG_0410.jpg  (img_0410.jpg.exe)

11 / 68    (Adware)
http://tr.im/o21  (kerish doctor 2015 4.exe)

13 / 68    (PUP)
http://tr.im/o44  (registrycleanersetup.exe)

1 / 68      (Adware)
http://tr.im/4t2dz  (sdformatter3_1.rar.exe)

The following file have been seen to comunicate with tr.im in live environments.

Remove Malware from tr.im - Powered by Reason Core Security