xpath.syncrvprodist.com

HugeDomains.com

Domain Information

The domain xpath.syncrvprodist.com registered by HugeDomains.com was initially registered in March of 2016 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
DROPCATCH.COM 929 LLC

Server location:
Virginia, United States (US)

Create date:
Thursday, March 3, 2016

Expires date:
Friday, March 3, 2017

Updated date:
Friday, March 4, 2016

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.Revizer.V
100.00%

VIPRE Antivirus
Revizer, Threat.5063086, Trojan.Win32.Generic
85.71%

avast!
NSIS:Adware-OA [PUP], Dropper-gen [Drp], NSIS:Adware-QF [Adw], NSIS:Adware-PH [Adw]
57.14%

ESET NOD32
Win32/AdWare.AddLyrics.BO (variant), Win32/Adware.AddLyrics.CG (variant), Win32/AdWare.AddLyrics.BJ
57.14%

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.144858, Application.Generic.779155, Gen:Trojan.Heur.RP.ouW@a47187ei
42.86%

Baidu Antivirus
Adware.Win32.AddLyrics
42.86%

Malwarebytes
PUP.Optional.ReMarkable.A, PUP.Optional.Graftor, PUP.Optional.AdLyrics
42.86%

AVG
Generic_r, AdLoad.K, Generic5
42.86%

MicroWorld eScan
Gen:Variant.Adware.Graftor.144858, Application.Generic.779155
28.57%

F-Secure
Gen:Variant.Adware.Graftor.144858, Gen:Trojan.Heur.RP.ouW@a47187ei
28.57%

Dr.Web
Trojan.Revizer.61, Trojan.Revizer.100
28.57%

G Data
Gen:Variant.Adware.Graftor.144858, NSIS.Adware.AddLyrics
28.57%

K7 AntiVirus
Adware
28.57%

Agnitum Outpost
PUA.AddLyrics
28.57%

Trend Micro House Call
Suspicious_GEN.F47V1007, Suspicious_GEN.F47V0818
28.57%

The domain xpath.syncrvprodist.com has been seen to resolve to the following 11 IP addresses.

ec2-52-4-72-137.compute-1.amazonaws.com
July 17, 2016

ec2-107-23-198-240.compute-1.amazonaws.com
July 17, 2016

ec2-52-20-104-240.compute-1.amazonaws.com
May 18, 2016

ec2-107-23-195-178.compute-1.amazonaws.com
May 18, 2016

ec2-52-200-243-123.compute-1.amazonaws.com
April 21, 2016

ec2-54-152-144-243.compute-1.amazonaws.com
April 21, 2016

January 4, 2015

January 4, 2015

January 4, 2015

September 15, 2014

September 15, 2014

File downloads found at URLs served by xpath.syncrvprodist.com.

3 / 68      (Adware)

3 / 68      (Adware)

9 / 68      (Adware)

23 / 68    (Adware)

4 / 68      (Adware)

23 / 68    (Adware)

6 / 68      (Adware)

The following 51 files have been seen to comunicate with xpath.syncrvprodist.com in live environments.

 
Latest 20 of 77 files

URL:
http://xpath.syncrvprodist.com/

Google Analytics:
UA-7117339

Title:
“HugeDomains.com - SyncRvProdist.com is for sale (Sync Rv Prodist)”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Microsoft-IIS/8.5 (ASP.NET)

30 of 50 related domains