The domain www.powerpackmtm.com is registered by proxy through GODADDY.COM, LLC and was originally registered in November of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Virginia, United States (US)
Tuesday, November 20, 2012
Sunday, November 20, 2016
Saturday, November 21, 2015
AS14618 AMAZON-AES - Amazon.com, Inc.
Detections (87% detected)
Win32.Sector.21, Trojan.KillFiles.12939, Adware.Downware.1308, Adware.PowerPack.2, Adware.PowerPack.29, Adware.PowerPack.18
Win32:Rootkit-gen [Rtk], Win32:Linkular-D [Adw], Win32:Malware-gen, Adware-gen [Adw], Evo-gen [Susp]
Adware.BrowseFox/Variant, Trojan.Agent/Gen-DarkKomet, PUP.Linkular/Variant
Application.Win32.Linkular.A, ApplicUnwnt, Application.Win32.Linkular.AY
W32/Sality.AT, Adware/Linkun.453633, APPL/Linkular.A, Adware/Linkular.D, Adware/Linkular.453592, APPL/LinkularD.A.3, ADWARE/Linkular.D
PUP.Installer.Linkular.Q, PUP.Installer.Linkular.K, PUP.Linkular.Company.Installer (M)
Trojan-Clicker/W32.Linkun.453633, Trojan-Clicker/W32.Linkun.456240.B, Trojan-Clicker/W32.Linkun.453776, Trojan-Clicker/W32.Linkun.458488
Trojan.Nsis.KillFiles.cwbfhm, Riskware.Nsis.Adload.dcibcg, Riskware.Win32.Linkular.dbpxeq, Riskware.Nsis.PowerPack.cwdxyp
W32/Sality.gen2, W32/A-951144e2, W32/Linkun.A (exact, not disinfectable)
K7 Gateway Antivirus
The domain www.powerpackmtm.com has been seen to resolve to the following IP address.
March 7, 2014
File downloads found at URLs served by www.powerpackmtm.com.
Amazon Web Services (AWS), running an EC2 instance