www.hurricane-file.net

ziv dascalu

Domain Information

The domain www.hurricane-file.net registered by ziv dascalu was initially registered in September of 2014 through GANDI SAS. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
GANDI SAS

Server location:
Oregon, United States (US)

Create date:
Wednesday, September 24, 2014

Expires date:
Thursday, September 24, 2015

Updated date:
Wednesday, September 24, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (86% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.Amonetize
85.71%

Agnitum Outpost
PUA.Amonetize
85.71%

Dr.Web
Adware.Downware.8618
85.71%

Zillya! Antivirus
Adware.Amonetize.Win32.1272
85.71%

AhnLab V3 Security
PUP/Win32.Amonetiz
85.71%

ESET NOD32
Win32/Amonetize.BR (variant)
85.71%

AVG
Generic_r
85.71%

Panda Antivirus
Trj/Genetic.gen
85.71%

Reason Heuristics
PUP.Installer.ShetefSolutionsConsulting1998.BB, PUP.Installer.ShetefSolutionsConsulting1998.?, PUP.Installer.ShetefSolutionsConsulting1998.g
85.71%

McAfee
Artemis!756E2715B8F8, Artemis!DD5F91ACEB5F, Artemis!DCABF01C7F51
42.86%

NANO AntiVirus
Riskware.Win32.Downware.dfqeij
28.57%

Baidu Antivirus
Adware.Win32.Amonetize
28.57%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A
14.29%

F-Secure
Application:W32/Generic.70053c248f!Online
14.29%

Fortinet FortiGate
Riskware/Amonetize
14.29%

The domain www.hurricane-file.net has been seen to resolve to the following 3 IP addresses.

ec2-54-245-104-86.us-west-2.compute.amazonaws.com
November 29, 2014

ec2-54-214-33-160.us-west-2.compute.amazonaws.com
October 9, 2014

ec2-54-214-247-254.us-west-2.compute.amazonaws.com
September 28, 2014

File downloads found at URLs served by www.hurricane-file.net.

The following 5 files have been seen to comunicate with www.hurricane-file.net in live environments.

URL:
http://www.hurricane-file.net/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Apache/2.2.29 (Amazon)