fdheh.trackvoluum.com

Super Privacy Service c/o Dynadot

Domain Information

The domain fdheh.trackvoluum.com registered by Super Privacy Service c/o Dynadot was initially registered in June of 2013 through DYNADOT, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
DYNADOT, LLC

Server location:
Virginia, United States (US)

Create date:
Friday, June 28, 2013

Expires date:
Tuesday, June 28, 2022

Updated date:
Monday, December 14, 2015

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.CoolMirage, PUP.Installer.CoolMirage, PUP.CoolMirage.VASSANAKONGSOONGNERN.Installer (M), PUP.PuvanatP.Installer (M), PUP.CoolMirage.VASSANAK.Installer (M)
100.00%

VIPRE Antivirus
Threat.4783938, CoolMirage Ltd
33.33%

Dr.Web
Adware.Yontoo.54
33.33%

K7 AntiVirus
Adware
33.33%

AhnLab V3 Security
Win-PUP/CrossRider
33.33%

AVG
Generic
33.33%

McAfee
Artemis!A14D7D508650, Artemis!894CFAF9FF3B
22.22%

Kaspersky
not-a-virus:Downloader.Win32.TornTV
22.22%

Baidu Antivirus
Hacktool.Win32.TornTV
22.22%

Sophos
CoolMirage
22.22%

Qihoo 360 Security
Win32/Virus.Downloader.e28
11.11%

Trend Micro House Call
Suspicious_GEN.F47V0130
11.11%

G Data
NSIS.Application.TornTV
11.11%

Vba32 AntiVirus
Downloader.TornTV
11.11%

The domain fdheh.trackvoluum.com has been seen to resolve to the following 6 IP addresses.

ec2-52-22-227-193.compute-1.amazonaws.com
August 28, 2016

ec2-52-22-240-225.compute-1.amazonaws.com
May 16, 2016

ec2-52-72-150-228.compute-1.amazonaws.com
May 16, 2016

ec2-54-173-35-140.compute-1.amazonaws.com
January 28, 2016

ec2-54-165-90-204.compute-1.amazonaws.com
January 28, 2016

ec2-52-20-94-168.compute-1.amazonaws.com
January 28, 2016

File downloads found at URLs served by fdheh.trackvoluum.com.

 
Latest 30 of 32 download URLs

The following file have been seen to comunicate with fdheh.trackvoluum.com in live environments.

URL:
http://fdheh.trackvoluum.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

SSL certificate subject:
CN=*.trackvoluum.com, OU=Domain Control Validated - RapidSSL(R), OU=See www.rapidssl.com/resources/cps (c)13, OU=GT89093649, SERIALNUMBER=tIMieP0cKNC4pSv-3uXEDsTTozrJ1u8p

SSL certificate issuer:
CN=RapidSSL CA, O="GeoTrust, Inc.", C=US

Web server:
Voluum-Traffic/1.0