ttb.mediaplayerinstaller.com

Whois Privacy Protection Service, Inc.  (Proxy Registrant)

Domain Information

The domain ttb.mediaplayerinstaller.com is registered by proxy through NAME.COM, INC. and was originally registered in September of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Remove Malware from ttb.mediaplayerinstaller.com - Powered by Reason Core Security
Registrar:
NAME.COM, INC.

Server location:
Oregon, United States (US)

Create date:
Tuesday, September 04, 2012

Expires date:
Sunday, September 04, 2016

Updated date:
Wednesday, March 18, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Scanner detections:
Detections  (90% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.BundloreLimited.F, PUP.Optional.Installer.I, PUP.Installer.LunacomInteractive.F, PUP.Installer.OUTBROWSE.F, PUP.Installer.TuguuSLU.F, PUP.Installer.InstallManager.F, PUP.Installer.TuguuSL.F, PUP.Installer.InstallationSafe.F, PUP.Bundler.Tuguu, PUP.NanningweiwuTechnologycoltd.Installer (M), PUP.Tuguu.TuguuU.Bundler (M), PUP.Softpulse.PluginUpdate.Bundler (M), PUP.Tuguu.tuguusl.Bundler (M), PUP.Adknowledge.INSTALLTHIS.Installer (M), PUP.Tuguu.LunacomInteractive.Bundler (M), PUP.Tuguu.Bundler (M), PUP.Adknowledge.SETUPDOTEXE.Bundler (M), PUP.Air Software.AirSoftware.Bundler (M)
100.00%

Dr.Web
Trojan.DownLoad3.30945, riskware program Program.Unwanted.79, Trojan.DownLoader10.50571, Adware.Downware.2081, Trojan.Packed.24553
57.78%

VIPRE Antivirus
Bundlore, Threat.4783235, Threat.4150696, Threat.4784938, Threat.4783262, Trojan.Win32.Generic, Threat.4778314
53.33%

McAfee
Artemis!05B6AD6EFB32, CryptDomaIQ, Adware-DomaIQ, Artemis!7FA7B38A12E2, Trojan.Artemis!D5E91201901F, Artemis!D67B4F803A1B
48.89%

Malwarebytes
PUP.Optional.Domalq, PUP.Optional.OutBrowse, PUP.Optional.BundleInstaller.A, PUP.Optional.Bundlore, PUP.Optional.AirAdInstaller
48.89%

Agnitum Outpost
Trojan.Agent, PUA.DomaIQ, Adware.Agent, Riskware.Agent, PUA.AirAd, PUA.Downloader, Adware.DomaIQ, PUA.Agent, PUA.AirAdInstaller
48.89%

avast!
PUP-gen [PUP], DomaIQ-AP [PUP], DomaIQ-AG [PUP], Adware-gen [Adw], Win32:Adware-gen [Adw], DomaIQ-AT [PUP], Win32:PUP-gen [PUP]
46.67%

AVG
Adware Skodna.Bundle_r.O, Generic, Lunac, Adware Skodna.Bundle_r.P, MalSign.Bundlo, Adware Skodna.Generic_r, Adware DomaIQ.BM
46.67%

F-Prot
W32/MSIL_Troj.CL2.gen, W32/DomaIQ.F.gen, W32/A-671e9403, W32/MSIL_Troj.CL.gen, W32/S-c30833b2, W32/A-c255719d, W32/DomaIQ.G.gen
46.67%

NANO AntiVirus
Trojan.Win32.DownLoader10.csdhkt, Trojan.Win32.Generic.cthmwf, Riskware.Win32.DomaIQ.cspbhg, Trojan.Win32.PayInt.cqkalc
46.67%

Avira AntiVirus
TR/DomaIQAT.A, APPL/Downloader.Gen, TR/Drop.Agent.457056, APPL/DomaIQ.Gen7, APPL/DomaIQ.AB, SPR/Bundlore.A, ADWARE/Adware.Gen
46.67%

K7 AntiVirus
Unwanted-Program , Trojan
46.67%

K7 Gateway Antivirus
Unwanted-Program , Trojan
46.67%

ESET NOD32
Win32/DomaIQ.AL potentially unwanted application, Win32/OutBrowse.G potentially unwanted application, MSIL/DomaIQ.B potentially unwanted application
44.44%

Sophos
DomainIQ pay-per install, OutBrowse Revenyou, Generic PUA OM, Bundlore, Generic PUA GI, PUA 'DomainIQ pay-per install', iBryte Optimum Installer
44.44%

The domain ttb.mediaplayerinstaller.com has been seen to resolve to the following 8 IP addresses.

April 14, 2015

April 1, 2015

ec2-54-201-201-245.us-west-2.compute.amazonaws.com
June 5, 2014

ec2-50-112-177-75.us-west-2.compute.amazonaws.com
May 21, 2014

ec2-54-213-33-153.us-west-2.compute.amazonaws.com
May 1, 2014

ec2-54-186-89-114.us-west-2.compute.amazonaws.com
March 14, 2014

ec2-54-244-32-152.us-west-2.compute.amazonaws.com
February 8, 2014

ec2-54-218-45-67.us-west-2.compute.amazonaws.com
December 26, 2013

File downloads found at URLs served by ttb.mediaplayerinstaller.com.

 
Latest 30 of 59 download URLs

URL:
http://ttb.mediaplayerinstaller.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx

Remove Malware from ttb.mediaplayerinstaller.com - Powered by Reason Core Security