ttb.defiletake.com

WHOIS PRIVACY PROTECTION SERVICE, INC.  (Proxy Registrant)

Domain Information

The domain ttb.defiletake.com is registered by proxy through ENOM, INC. and was originally registered in June of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Beaumaris, Victoria within Australia which resides on the Asia Pacific Network Information Centre network.
Registrar:
ENOM, INC.

Server location:
Victoria, Australia (AU)

Create date:
Monday, June 1, 2015

Expires date:
Wednesday, June 1, 2016

Updated date:
Monday, June 1, 2015

ASN:
AS133618 TRELLIAN-AS-AP Trellian Pty. Limited,AU

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Softpulse.PLUGINUPDATE.Bundler (M), PUP.Softpulse.PLUGINUP.Bundler (M), PUP.Softpulse (M)
100.00%

The domain ttb.defiletake.com has been seen to resolve to the following 5 IP addresses.

lb-182-241.above.com
September 16, 2016

September 2, 2016

June 2, 2016

ec2-54-69-125-213.us-west-2.compute.amazonaws.com
January 27, 2016

ec2-54-191-36-84.us-west-2.compute.amazonaws.com
January 27, 2016

File downloads found at URLs served by ttb.defiletake.com.

 
Latest 30 of 71 download URLs

The following 13 files have been seen to comunicate with ttb.defiletake.com in live environments.

URL:
http://ttb.defiletake.com/

Web server:
nginx (PHP/5.3.10-1ubuntu3.17)