www.fastmediaplayer.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.fastmediaplayer.net is registered by proxy through GODADDY.COM, LLC and was originally registered in January of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Wednesday, January 7, 2015

Expires date:
Saturday, January 7, 2017

Updated date:
Monday, December 21, 2015

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.IMALI, PUP.IMALI.Installer, Threat.Win.Reputation.IMP, PUP.IMALI.IMALINIMEDIA.Installer (M), PUP.SoftPulse.YumonSystem.Installer (M), PUP.IMALI.IMALINIM.Installer (M), PUP.Installer.Bundler.Installer.Meta (M), PUP.IMALI (M)
100.00%

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.179625, Gen:Variant.Adware.Mplug.39
7.14%

avast!
Win32:Adware-gen [Adw], Win32:Rootkit-gen [Rtk]
7.14%

VIPRE Antivirus
Threat.4150696
7.14%

ESET NOD32
Win32/Adware.Imali.B application
7.14%

F-Secure
Gen:Variant.Graftor.179625, Gen:Variant.Adware.Mplug
7.14%

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.179625, Gen:Variant.Adware.Mplug.39
7.14%

MicroWorld eScan
Gen:Variant.Adware.Graftor.179625, Gen:Variant.Adware.Mplug.39
7.14%

K7 AntiVirus
Adware
7.14%

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
7.14%

Bitdefender
Gen:Variant.Graftor.179625, Gen:Variant.Adware.Mplug.39
7.14%

Dr.Web
Adware.Downware.10685, Adware.Downware.10514, Adware.Downware.10685, Adware.Downware.10308
7.14%

Avira AntiVirus
ADWARE/Adware.Gen7
7.14%

G Data
Gen:Variant.Graftor.179625, Gen:Variant.Adware.Mplug.39
7.14%

AVG
Adware Generic6, Adware Generic6.AARZ
7.14%

The domain www.fastmediaplayer.net has been seen to resolve to the following 2 IP addresses.

ec2-52-1-45-42.compute-1.amazonaws.com
June 30, 2015

209.81.59.108.bc.googleusercontent.com
April 12, 2015

File downloads found at URLs served by www.fastmediaplayer.net.

1 / 68      (Malware)

 
Latest 30 of 42 download URLs

The following 1132 files have been seen to comunicate with www.fastmediaplayer.net in live environments.

 
Latest 20 of 1,157 files

URL:
http://www.fastmediaplayer.net/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx