fasternations.net

Amir Derbinin

Domain Information

The domain fasternations.net registered by Amir Derbinin was initially registered in September of 2014 through EVOPLUS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Registrar:
EVOPLUS LTD

Server location:
Dublin City, Ireland (IE)

Create date:
Sunday, September 7, 2014

Expires date:
Wednesday, September 7, 2016

Updated date:
Monday, September 7, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (75% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/Adware.MultiPlug.DZ application
100.00%

Dr.Web
Trojan.WebPick.3219, Trojan.Crossrider.36840, Trojan.Crossrider1.31000
77.78%

AVG
Adware Generic6.BHF
77.78%

Norman
Gen:Variant.Adware.Mplug.21, Gen:Variant.Adware.Kazy.511922, Gen:Variant.Downloader.188
77.78%

avast!
Win32:FakeDownload-G [PUP], Win32:Agent-AYLT [PUP]
77.78%

McAfee
Program.MultiPlug-FTL
66.67%

Emsisoft Anti-Malware
Gen:Variant.Adware.Mplug.21, Gen:Variant.Adware.Kazy.511922
66.67%

F-Secure
Gen:Variant.Adware.Mplug, Variant.Downloader.188, Variant.Adware.Kazy, Variant.Adware.MultiPlug
55.56%

VIPRE Antivirus
MultiPlug, Threat.5180739
44.44%

Lavasoft Ad-Aware
Gen:Variant.Adware.Mplug.21, Gen:Variant.Adware.Kazy.511922
33.33%

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug, not-a-virus:HEUR:AdWare.Win32.MultiPlug
22.22%

MicroWorld eScan
Gen:Variant.Adware.Mplug.21, Gen:Variant.Adware.Kazy.511922
22.22%

nProtect
Trojan-Clicker/W32.MultiPlug.999424.F, Trojan-Clicker/W32.MultiPlug.999424.I
22.22%

Quick Heal
Adware.MultiPlug.GN5
22.22%

Malwarebytes
PUP.Optional.MultiPlug
22.22%

The domain fasternations.net has been seen to resolve to the following 2 IP addresses.

ec2-54-72-9-115.eu-west-1.compute.amazonaws.com
September 14, 2016

ec2-54-244-95-35.us-west-2.compute.amazonaws.com
November 18, 2015

File downloads found at URLs served by fasternations.net.

3 / 68      (PUP)
http://fasternations.net/.../Download.exe  (852d282ca8e84b1718c2182e96cd0de8)

3 / 68      (PUP)
http://fasternations.net/.../Download.exe  (33b28c30e858dad071d797f36ecd2343)

6 / 68      (PUP)

0 / 68
http://fasternations.net/null  (bmwx6furkansevke.rar.exe)

0 / 68
http://fasternations.net/null  (keygen.zip.exe)

7 / 68      (PUP)
http://fasternations.net/.../chulla quiteno.exe  (4c7b29cbb8c8072e02f515195c5c6f7e)

0 / 68
http://fasternations.net/null  (downloader_for_pokemon- fire red version.exe)

9 / 68      (PUP)
http://fasternations.net/.../Download.exe  (c9c1ea770cb267b3c6a83c71c8180ddc)

30 / 68    (PUP)
http://fasternations.net/.../Download.exe  (d606573b02c2a7cfd076a3f8f673da48)

29 / 68    (PUP)
http://fasternations.net/.../Download.exe  (42a34b68db409afaaeaf9fce9e31e71b)

The following 253 files have been seen to comunicate with fasternations.net in live environments.

 
Latest 20 of 267 files