fasternations.com

Amir Derbinin

Domain Information

The domain fasternations.com registered by Amir Derbinin was initially registered in September of 2014 through EVOPLUS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Registrar:
EVOPLUS LTD

Server location:
Dublin City, Ireland (IE)

Create date:
Sunday, September 7, 2014

Expires date:
Wednesday, September 7, 2016

Updated date:
Monday, September 7, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (89% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/Adware.MultiPlug.DZ application
100.00%

avast!
Win32:Agent-AUVV [Trj], Win32:FakeDownload-G [PUP], Win32:Agent-AYLT [PUP]
94.12%

Emsisoft Anti-Malware
Gen:Trojan.Heur2.FU.9uW@aSdgm0ei, Gen:Variant.Adware.Mplug.21, Gen:Variant.Adware.Kazy.511922, Gen:Variant.Adware.MultiPlug.20
88.24%

AVG
Adware Generic6.BHF, Adware Generic6.BHT
88.24%

Norman
Gen:Trojan.Heur2.FU.9uW@aSdgm0ei, Gen:Trojan.Heur.JP.9uW@aWZVa9pi, Gen:Variant.Adware.Kazy.511922, Gen:Variant.Adware.Mplug.21
88.24%

Dr.Web
Trojan.WebPick.3190, Trojan.WebPick.3219, Trojan.Crossrider.36840, Trojan.Crossrider1.31000
82.35%

McAfee
Program.MultiPlug-FTL
58.82%

VIPRE Antivirus
Threat.5180739
47.06%

Lavasoft Ad-Aware
Gen:Trojan.Heur2.FU.9uW@aSdgm0ei, Gen:Variant.Adware.Mplug.21, Gen:Variant.Adware.Kazy.511922
29.41%

F-Secure
Gen:Variant.Adware.Mplug, Gen:Variant.Adware.Kazy, Variant.Adware.MultiPlug
29.41%

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug, not-a-virus:HEUR:AdWare.Win32.MultiPlug
23.53%

Avira AntiVirus
ADWARE/MultiPlug.Gen7, W32/Chir.B
23.53%

MicroWorld eScan
Gen:Trojan.Heur2.FU.9uW@aSdgm0ei, Gen:Variant.Adware.Mplug.21, Gen:Variant.Adware.Kazy.511922
17.65%

NANO AntiVirus
Riskware.Win32.MultiPlug.djsutk
17.65%

Bitdefender
Gen:Trojan.Heur2.FU.9uW@aSdgm0ei, Gen:Variant.Adware.Mplug.21, Gen:Variant.Adware.Kazy.511922
17.65%

The domain fasternations.com has been seen to resolve to the following 8 IP addresses.

ec2-54-72-9-115.eu-west-1.compute.amazonaws.com
September 13, 2016

ec2-52-24-5-45.us-west-2.compute.amazonaws.com
February 12, 2016

ec2-54-213-23-40.us-west-2.compute.amazonaws.com
September 16, 2015

ec2-52-26-16-139.us-west-2.compute.amazonaws.com
September 16, 2015

ec2-52-25-206-149.us-west-2.compute.amazonaws.com
September 16, 2015

ec2-52-11-81-80.us-west-2.compute.amazonaws.com
September 16, 2015

ec2-54-213-128-72.us-west-2.compute.amazonaws.com
May 3, 2015

ec2-54-69-220-239.us-west-2.compute.amazonaws.com
May 3, 2015

File downloads found at URLs served by fasternations.com.

0 / 68
http://fasternations.com/.../Download.exe  (67b68ffc44472cd968cd3f43ff15df5c)

5 / 68      (PUP)
http://fasternations.com/.../Download.exe  (2c7bb335084a0293e029b93ab177f47c)

5 / 68      (PUP)

9 / 68      (PUP)
http://fasternations.com/.../Download.exe  (17e30cb56c8e1648a2568e0713a57f2c)

7 / 68      (PUP)
http://fasternations.com/.../Download.exe  (a3d9f3b1e68bae7d924c4effd4053bd2)

7 / 68      (PUP)
http://fasternations.com/.../Download.exe  (6e0364e5c6f4b8f045f781daed848daa)

6 / 68      (PUP)
http://fasternations.com/.../Download.exe  (bf1b431a9a1122ad62d9559d44b83003)

8 / 68      (PUP)
http://fasternations.com/.../Download.exe  (1c74226a10853e1f9de503a1e768d675)

9 / 68      (PUP)
http://fasternations.com/.../Download Shollu Free 3.10 , Pengingat Sholat | Tutorials and Software.exe  (download shollu free 3.10 , pengingat sholat - tutorials and software.exe)

11 / 68    (PUP)

0 / 68
http://fasternations.com/null  (simpleserver.exe)

24 / 68    (PUP)
http://fasternations.com/.../Download.exe  (067541d417d519b77ea504841678d549)

The following 275 files have been seen to comunicate with fasternations.com in live environments.

 
Latest 20 of 294 files

URL:
http://fasternations.com/

Title:
“Welcome to nginx!”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
ngx_openresty