best-new-zip-my.info

Ivan Prihodko

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
Domain.com,LLC (R656-LRMS)

Server location:
Oregon, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.WebPick.Installer.Q, PUP.Optional.Installer.X, PUP.Installer.SergeyPetrov.K, Adware.WebPick.Installer.S, Adware.WebPick.Installer.V, Adware.WebPick.Installer.K, Adware.WebPick.Installer.X, Adware.WebPick.Installer.BB, Adware.WebPick.Installer.H, Adware.WebPick.Installer.e, Adware.WebPick.Installer.R, Adware.WebPick.Installer.g, Adware.WebPick.Installer.w, Adware.WebPick.Installer.I, Adware.WebPick.Installer.j, Adware.WebPick.Installer.q, Adware.AdInjector.Installer.WebPick, Adware.WebPick.Installer (M), Adware (M)
100.00%

Malwarebytes
PUP.Optional.Installrex, PUP.Optional.InstalleRex, PUP.Optional.Tarma, PUP.Optional.Installex
87.50%

avast!
Win32:InstalleRex-AI [PUP], Win32:InstalleRex-BI [PUP], Win32:InstalleRex-AR [PUP], Win32:InstalleRex-Y [PUP], Win32:InstalleRex-AH [PUP]
87.50%

Kaspersky
not-a-virus:Downloader.Win32.AdLoad, Trojan.Win32.AntiFW, not-a-virus:HEUR:Downloader.Win32.AdLoad
87.50%

Comodo Security
Application.Win32.InstalleRex.KG
87.50%

Dr.Web
Adware.Downware.1541, Trojan.WebPick.29, Adware.Downware.1719, Adware.Downware.1442, Adware.Downware.2108, Trojan.WebPick.2735
87.50%

VIPRE Antivirus
Trojan.Win32.Generic, Installerex/WebPick, Threat.4150696
87.50%

Avira AntiVirus
Adware/InstallRex.X, TR/Kazy.324119.11, Adware/InstallRex.bza, ADWARE/InstallRex.Gen, Adware/Adload.ger, TR/AntiFW.b.106
87.50%

Vba32 AntiVirus
Downloader.AdLoad, Downware.TSU, AdWare.Agent
87.50%

AVG
MalSign.Generic, Skodna.Generic, Skodna.Bundle, Trojan horse Crypt_s.GAB, Adware Skodna.Bundle, InstallRex
87.50%

Sophos
InstallRex, PUA 'InstallRex'
83.33%

G Data
Trojan.Generic.10396428, Win32.Application.InstalleRex, Application.Generic.621656, Trojan.Generic.11548988, Win32.Application.EZDownloader
83.33%

NANO AntiVirus
Trojan.Win32.AntiFW.cvgqot, Riskware.Win32.Downware.cscobj, Riskware.Win32.Downware.crfmjd, Riskware.Win32.Downware.ctkpgp
83.33%

AhnLab V3 Security
PUP/Win32.TSULoader
79.17%

Rising Antivirus
PE:PUF.InstallRex!1.9E4C, PE:Trojan.AntiFW!6.17F7, PE:Trojan.AntiFW!6.14A6, PE:Malware.Agent!6.25, PE:Trojan.AntiFW!6.16DE
79.17%

The domain best-new-zip-my.info has been seen to resolve to the following 3 IP addresses.

148.162.96.66.static.eigbox.net
September 5, 2014

ec2-54-186-255-26.us-west-2.compute.amazonaws.com
April 4, 2014

ec2-54-201-215-30.us-west-2.compute.amazonaws.com
January 16, 2014

File downloads found at URLs served by best-new-zip-my.info.

 
Latest 30 of 48 download URLs

The following file have been seen to comunicate with best-new-zip-my.info in live environments.

URL:
http://best-new-zip-my.info/

Title:
“Domain.com”

Description:
“Small business web hosting offering additional business services such as: domain name registrations, email accounts, web services, FrontPage help, online community resources and various small business solutions.”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Apache/2