cloudfront.systweak.com

WHOIS PRIVACY PROTECTION SERVICE, INC.  (Proxy Registrant)

Domain Information

The domain cloudfront.systweak.com is registered by proxy through ENOM, INC. and was originally registered in September of 2001. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Friday, September 28, 2001

Expires date:
Sunday, September 28, 2025

Updated date:
Monday, March 28, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (90% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Systweak.Installer.Meta (L), PUP.Optional.Systweak.X, PUP.Systweak.ThePhone.Installer.Meta (L), PUP.Systweak.Optional.Installer.Meta (L), PUP.SysTweak.Installer.Meta (L), PUP.Systweak (L), PUP.TuneUpPro (M), PUP.installCore (M)
100.00%

avast!
Win32:Malware-gen
4.44%

Malwarebytes
PUP.Optional.RegCleanerPro
2.22%

ESET NOD32
Win32/Systweak.D potentially unwanted application
2.22%

Dr.Web
Detection.Undefined
2.22%

The domain cloudfront.systweak.com has been seen to resolve to the following 84 IP addresses.

server-54-239-152-140.iad53.r.cloudfront.net
September 16, 2016

server-52-84-121-93.iad16.r.cloudfront.net
September 16, 2016

server-54-239-152-108.iad53.r.cloudfront.net
September 4, 2016

server-54-239-152-209.iad53.r.cloudfront.net
August 24, 2016

server-52-84-121-211.iad16.r.cloudfront.net
August 23, 2016

server-52-84-121-14.iad16.r.cloudfront.net
August 18, 2016

server-54-192-17-219.iad12.r.cloudfront.net
August 15, 2016

server-54-192-17-133.iad12.r.cloudfront.net
August 13, 2016

server-52-84-121-251.iad16.r.cloudfront.net
August 13, 2016

server-54-230-195-59.iad53.r.cloudfront.net
August 12, 2016

server-54-230-195-8.iad53.r.cloudfront.net
August 10, 2016

server-52-84-121-161.iad16.r.cloudfront.net
August 9, 2016

server-54-230-195-49.iad53.r.cloudfront.net
July 31, 2016

server-54-230-195-171.iad53.r.cloudfront.net
July 29, 2016

server-54-230-195-81.iad53.r.cloudfront.net
July 28, 2016

server-54-192-17-145.iad12.r.cloudfront.net
July 26, 2016

server-52-84-121-64.iad16.r.cloudfront.net
July 23, 2016

server-54-230-195-134.iad53.r.cloudfront.net
July 17, 2016

server-52-84-121-212.iad16.r.cloudfront.net
July 5, 2016

server-54-192-17-214.iad12.r.cloudfront.net
June 29, 2016

server-52-84-127-96.iad16.r.cloudfront.net
June 29, 2016

server-54-192-17-212.iad12.r.cloudfront.net
June 26, 2016

server-52-84-127-129.iad16.r.cloudfront.net
June 26, 2016

server-54-230-195-224.iad53.r.cloudfront.net
June 26, 2016

server-54-192-17-44.iad12.r.cloudfront.net
June 24, 2016

server-52-84-127-186.iad16.r.cloudfront.net
June 22, 2016

server-52-84-127-237.iad16.r.cloudfront.net
June 19, 2016

server-54-230-195-94.iad53.r.cloudfront.net
June 19, 2016

server-54-192-17-57.iad12.r.cloudfront.net
June 19, 2016

server-54-230-195-139.iad53.r.cloudfront.net
June 7, 2016

 
Showing 30 of 84 IP Addresses

File downloads found at URLs served by cloudfront.systweak.com.

1 / 68      (Adware)

1 / 68      (PUP)

0 / 68

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

2 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://cloudfront.systweak.com/.../rcpsetup17970.exe  (d79021307e0aaf058cf4719217471389)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

3 / 68      (PUP)

0 / 68

 
Latest 30 of 1,058 download URLs

The following 12 files have been seen to comunicate with cloudfront.systweak.com in live environments.

URL:
http://cloudfront.systweak.com/

Network:
Amazon Cloudfront

Web server:
AmazonS3