a.allstate-final.xyz

Domain Information

Server location:
Oregon, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer, Threat.WebPick.RodionVeresev, Threat.Win.Reputation.IMP
100.00%

Dr.Web
Trojan.Crossrider1.1621, Trojan.Crossrider1.25958, Trojan.DownLoader13.1348, Trojan.DownLoader13.2483
17.39%

McAfee
Artemis!9B8D97161AE5, MultiPlug-FWG, Program.MultiPlug-FWG
17.39%

AVG
Adware Skodna.Generic, Generic6, Adware Generic6.AIXT, Adware Generic6.AJLL
17.39%

Fortinet FortiGate
Riskware/ReImageRepair, Riskware/MultiPlug, Riskware/Badur
13.04%

Zillya! Antivirus
Downloader.Agent.Win32.241821, Adware.MultiPlug.Win32.285477, Adware.MultiPlugGen.Win32.1
13.04%

Lavasoft Ad-Aware
Adware.Mplug.IP, Gen:Variant.Adware.MPlug.38, Gen:Variant.Adware.Mplug.36
13.04%

Emsisoft Anti-Malware
Adware.Mplug.IP, Gen:Variant.Adware.MPlug.38, Gen:Variant.Adware.Mplug.36
13.04%

ESET NOD32
Win32/Adware.MultiPlug.JH application, Win32/Adware.MultiPlug.JB application, Win32/Adware.MultiPlug.JI application
13.04%

F-Secure
Adware.Mplug.IP, Gen:Variant.Adware.MPlug, Gen:Variant.Adware.Mplug
13.04%

MicroWorld eScan
Adware.Mplug.IP, Gen:Variant.Adware.MPlug.38, Gen:Variant.Adware.Mplug.36
13.04%

Bitdefender
Adware.Mplug.IP, Gen:Variant.Adware.MPlug.38, Gen:Variant.Adware.Mplug.36
13.04%

AhnLab V3 Security
PUP/Win32.MultiPlug
13.04%

G Data
Adware.Mplug.IP, Gen:Variant.Adware.MPlug.38, Gen:Variant.Adware.Mplug.36
13.04%

Vba32 AntiVirus
suspected of Heur.Malware-Cryptor.Multiplug
13.04%

The domain a.allstate-final.xyz has been seen to resolve to the following 2 IP addresses.

ec2-54-149-241-47.us-west-2.compute.amazonaws.com
May 6, 2015

ec2-54-69-228-231.us-west-2.compute.amazonaws.com
May 6, 2015

File downloads found at URLs served by a.allstate-final.xyz.

The following 3 files have been seen to comunicate with a.allstate-final.xyz in live environments.