f.websited.link

Domain Information

Server location:
Oregon, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Malware distribution  (97% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP, PUP.installCore.DestinyD.Installer (M)
92.86%

avast!
Win32:MultiPlug-ZC [PUP], Win32:FakeDownload-F [PUP], Win32:FakeDownload-E [PUP]
21.43%

Dr.Web
Trojan.Crossrider1.29239, Trojan.Fakealert.50690
17.86%

Emsisoft Anti-Malware
Gen:Variant.Adware.Mplug.41, Gen:Variant.Adware.Mplug.36, Adware.MultiPlug.KO, Gen:Variant.Razy.6292
17.86%

AVG
Adware Generic6.APLQ, Adware Generic6.APKW, Adware Generic6.APKD, Adware Generic6.APQB, Adware Generic6.APJI
17.86%

McAfee
MultiPlug-FXP, Program.MultiPlug-FXP, Program.MultiPlug-FXN
17.86%

F-Secure
Gen:Variant.Adware.Mplug, Variant.Razy.6292
14.29%

Lavasoft Ad-Aware
Gen:Variant.Adware.Mplug.41, Gen:Variant.Adware.Mplug.36, Adware.MultiPlug.KO
14.29%

ESET NOD32
Win32/Adware.MultiPlug.JZ application
14.29%

MicroWorld eScan
Gen:Variant.Adware.Mplug.41, Gen:Variant.Adware.Mplug.36, Adware.MultiPlug.KO
14.29%

K7 AntiVirus
Unwanted-Program
14.29%

Bitdefender
Gen:Variant.Adware.Mplug.41, Gen:Variant.Adware.Mplug.36, Adware.MultiPlug.KO
14.29%

G Data
Gen:Variant.Adware.Mplug.41, Gen:Variant.Adware.Mplug.36, Adware.MultiPlug.KO
14.29%

AhnLab V3 Security
PUP/Win32.MultiPlug
14.29%

Vba32 AntiVirus
suspected of Heur.Malware-Cryptor.Multiplug
14.29%

The domain f.websited.link has been seen to resolve to the following 8 IP addresses.

April 9, 2016

ec2-52-27-128-59.us-west-2.compute.amazonaws.com
July 16, 2015

ec2-52-27-128-56.us-west-2.compute.amazonaws.com
July 16, 2015

ec2-52-27-128-62.us-west-2.compute.amazonaws.com
July 16, 2015

ec2-52-26-142-209.us-west-2.compute.amazonaws.com
July 1, 2015

ec2-52-11-167-137.us-west-2.compute.amazonaws.com
July 1, 2015

ec2-54-69-228-231.us-west-2.compute.amazonaws.com
May 15, 2015

ec2-54-149-241-47.us-west-2.compute.amazonaws.com
May 15, 2015

File downloads found at URLs served by f.websited.link.

The following 6 files have been seen to comunicate with f.websited.link in live environments.