www.mp3rocketnowbest.com

Communigal Communication Ltd

Domain Information

The domain www.mp3rocketnowbest.com registered by Communigal Communication Ltd was initially registered in July of 2015 through GAL COMMUNICATION (COMMUNIGAL) LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Registrar:
GAL COMMUNICATION (COMMUNIGAL) LTD.

Server location:
Dublin City, Ireland (IE)

Create date:
Wednesday, July 15, 2015

Expires date:
Friday, July 15, 2016

Updated date:
Wednesday, July 15, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (97% detected)

Scan engine
Details
Detections

Reason Heuristics
Win32.Generic.SCCE.Installer.Meta, PUP.installCore.MP3TechSupport.Installer (M), PUP.installCore (M), PUP.installCore.MP3TechS.Installer (M)
92.31%

Dr.Web
Adware.OpenCandy.171, Adware.OpenCandy.163, Adware.OpenCandy.194, Win32.Parite.2
74.36%

VIPRE Antivirus
Opencandy, Trojan.Win32.Generic, Threat.4150696
74.36%

K7 AntiVirus
Unwanted-Program
71.79%

AVG
Generic, Win32/Parite
71.79%

Zillya! Antivirus
Downloader.Agent.Win32.260269, Trojan.Kryptik.Win32.805012, Downloader.Agent.Win32.284783
69.23%

Fortinet FortiGate
Riskware/OpenCandy
69.23%

Baidu Antivirus
Adware.Win32.OpenCandy
69.23%

SUPERAntiSpyware
PUP.MP3Rocket/Variant
66.67%

ESET NOD32
Win32/OpenCandy.E potentially unsafe (variant), Win32/OpenCandy.A potentially unsafe (variant)
56.41%

McAfee
Artemis!09672008FF00, Artemis!9834C63403AD, Artemis!26F4F093AD68, Artemis!433959388623, Artemis!03401FFC6A8D, Artemis!979B7B1460AD, Artemis!BCEFE6C98C14, Artemis!D8C15DE6EE7A
46.15%

avast!
Win32:Malware-gen, Win32:Parite
46.15%

Kaspersky
not-a-virus:Downloader.Win32.Agent, Virus.Win32.Parite
43.59%

Bkav FE
W32.HfsAdware
41.03%

Agnitum Outpost
Riskware.Agent
41.03%

The domain www.mp3rocketnowbest.com has been seen to resolve to the following 26 IP addresses.

July 18, 2016

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
July 17, 2016

ec2-54-200-224-121.us-west-2.compute.amazonaws.com
July 17, 2016

ec2-54-148-183-210.us-west-2.compute.amazonaws.com
July 17, 2016

ec2-54-186-99-90.us-west-2.compute.amazonaws.com
July 5, 2016

ec2-54-191-246-249.us-west-2.compute.amazonaws.com
June 27, 2016

ec2-52-33-46-229.us-west-2.compute.amazonaws.com
June 25, 2016

ec2-54-149-195-20.us-west-2.compute.amazonaws.com
June 25, 2016

ec2-52-41-114-34.us-west-2.compute.amazonaws.com
June 25, 2016

ec2-52-38-209-219.us-west-2.compute.amazonaws.com
June 4, 2016

ec2-52-33-165-25.us-west-2.compute.amazonaws.com
June 4, 2016

ec2-52-32-12-104.us-west-2.compute.amazonaws.com
June 4, 2016

ec2-52-25-41-73.us-west-2.compute.amazonaws.com
May 5, 2016

ec2-52-24-26-116.us-west-2.compute.amazonaws.com
May 5, 2016

ec2-54-148-57-212.us-west-2.compute.amazonaws.com
April 16, 2016

ec2-52-26-95-11.us-west-2.compute.amazonaws.com
April 16, 2016

ec2-54-69-198-37.us-west-2.compute.amazonaws.com
April 16, 2016

ec2-54-69-11-66.us-west-2.compute.amazonaws.com
January 30, 2016

ec2-52-88-159-85.us-west-2.compute.amazonaws.com
January 30, 2016

ec2-52-35-10-15.us-west-2.compute.amazonaws.com
January 30, 2016

ec2-54-191-37-5.us-west-2.compute.amazonaws.com
December 19, 2015

ec2-52-34-170-106.us-west-2.compute.amazonaws.com
December 19, 2015

ec2-52-25-23-136.us-west-2.compute.amazonaws.com
December 19, 2015

ec2-54-149-60-150.us-west-2.compute.amazonaws.com
October 12, 2015

ec2-54-148-75-228.us-west-2.compute.amazonaws.com
October 12, 2015

ec2-52-24-62-64.us-west-2.compute.amazonaws.com
October 12, 2015

File downloads found at URLs served by www.mp3rocketnowbest.com.

 
Latest 30 of 1,026 download URLs

The following 246 files have been seen to comunicate with www.mp3rocketnowbest.com in live environments.

TCP » 54.72.9.51:80

 
Latest 20 of 296 files