The domain adk2trk.cpmrocket.com registered by CPM Rocket S.L. was initially registered in March of 2013 through ARSYS INTERNET, S.L. D/B/A NICLINE.COM. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrant:
CPM Rocket S.L.
Registrar:
ARSYS INTERNET, S.L. D/B/A NICLINE.COM
Server location:
Virginia, United States (US)
Create date:
Monday, March 18, 2013
Expires date:
Monday, March 18, 2019
Updated date:
Monday, February 22, 2016
ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US
Scanner detections:
Detections (93% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.Amonetizeltd.g, Threat.Win.Reputation.IMP, PUP.Installer.ShetefSolutionsConsulting1998.g, PUP.Optional.Installer.X, PUP.Amonetize.Bundler (M)
93.33%
VIPRE Antivirus
Amonetize, Conduit, Trojan.Win32.Generic, Threat.4785227, Threat.4371328
46.67%
Malwarebytes
PUP.Optional.InstallMonetizer, PUP.Optional.Amonetize.A, PUP.Optional.Monetizer
40.00%
avast!
Win32:Amonetize-AX [PUP], Win32:Adware-BJY [PUP], Win32:Amonetize-M [PUP], Win32:Amonetize-BL [PUP], Win32:Amonetize-BJ [PUP]
40.00%
Sophos
Amonetize, PUA 'Amonetize'
33.33%
Dr.Web
Adware.Downware.1655, Adware.Downware.1575, Trojan.Amonetize.353, Adware.Downware.3925
33.33%
ESET NOD32
Win32/Amonetize.AA (variant), Win32/Amonetize.AJ (variant), Win32/Amonetize.AG (variant), Win32/Amonetize.AS (variant)
33.33%
Avira AntiVirus
ADWARE/Adware.Gen2
33.33%
McAfee
Artemis!D5F74C41F572, Adware-Amonetize!0CAB3BFD4893, Artemis!B7A1D9842512, Program.PUP-FBM, PUP-FBM!53823E68BFFE
33.33%
Trend Micro House Call
TROJ_GEN.F47V1219, TROJ_GEN.F47V0427, TROJ_GEN.F0CBOC0DDB4, TROJ_GEN.F47V0304
26.67%
AhnLab V3 Security
PUP/Win32.Amonetiz
26.67%
AVG
MalSign.Generic, Generic_r, Adware Generic_r.MG
26.67%
Baidu Antivirus
Adware.Win32.Amonetize
20.00%
MicroWorld eScan
Trojan.Generic.11241702, Trojan.Generic.11143391, Gen:Variant.Application.Bundler.Amonetize.14
20.00%
Bitdefender
Trojan.Generic.11241702, Trojan.Generic.11143391, Gen:Variant.Application.Bundler.Amonetize.14
20.00%
The domain adk2trk.cpmrocket.com has been seen to resolve to the following 22 IP addresses.
33.179.211.130.bc.googleusercontent.com
January 6, 2016
193.167.211.130.bc.googleusercontent.com
January 6, 2016
6.163.211.130.bc.googleusercontent.com
January 6, 2016
151.150.211.130.bc.googleusercontent.com
January 6, 2016
98.149.211.130.bc.googleusercontent.com
January 6, 2016
216.142.211.130.bc.googleusercontent.com
January 6, 2016
174.130.211.130.bc.googleusercontent.com
January 6, 2016
20.113.211.130.bc.googleusercontent.com
January 6, 2016
187.159.251.23.bc.googleusercontent.com
January 6, 2016
62.154.251.23.bc.googleusercontent.com
January 6, 2016
24.59.148.146.bc.googleusercontent.com
January 6, 2016
59.183.211.130.bc.googleusercontent.com
January 6, 2016
ec2-54-209-165-189.compute-1.amazonaws.com
September 7, 2014
ec2-54-209-99-13.compute-1.amazonaws.com
September 7, 2014
ec2-54-208-253-153.compute-1.amazonaws.com
September 7, 2014
ec2-54-208-196-64.compute-1.amazonaws.com
September 7, 2014
ec2-54-208-109-40.compute-1.amazonaws.com
September 7, 2014
ec2-54-86-243-123.compute-1.amazonaws.com
September 7, 2014
ec2-54-86-223-230.compute-1.amazonaws.com
September 7, 2014
ec2-54-86-91-8.compute-1.amazonaws.com
September 7, 2014
ec2-54-86-44-247.compute-1.amazonaws.com
September 7, 2014
ec2-54-85-248-48.compute-1.amazonaws.com
September 7, 2014
File downloads found at URLs served by adk2trk.cpmrocket.com.
The following 2 files have been seen to comunicate with adk2trk.cpmrocket.com in live environments.
Statistics are for the previous month.