files.7zip.me

Perfect Privacy, LLC  (Proxy Registrant)

Domain Information

The domain files.7zip.me is registered by proxy through Network Solutions, LLC R147-ME (2) and was originally registered in June of 2010. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Seattle, Washington within the United States. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
Network Solutions, LLC R147-ME (2)

Server location:
Washington, United States (US)

Create date:
Tuesday, June 15, 2010

Expires date:
Monday, June 15, 2020

Updated date:
Thursday, April 16, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc., US

Root domain:

Scanner detections:
Detections  (67% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.TomorrowSoftware.Deepwell.Bundler (M), PUP.ClickSta.Installer (M)
66.67%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A
33.33%

F-Secure
Application:W32/Generic.70053c248f!Online
33.33%

The domain files.7zip.me has been seen to resolve to the following 24 IP addresses.

server-54-192-19-39.iad12.r.cloudfront.net
July 5, 2016

server-54-192-19-237.iad12.r.cloudfront.net
July 5, 2016

server-54-192-19-226.iad12.r.cloudfront.net
July 5, 2016

server-54-192-19-223.iad12.r.cloudfront.net
July 5, 2016

server-54-192-19-192.iad12.r.cloudfront.net
July 5, 2016

server-54-192-19-176.iad12.r.cloudfront.net
July 5, 2016

server-54-192-19-156.iad12.r.cloudfront.net
July 5, 2016

server-54-192-19-62.iad12.r.cloudfront.net
July 5, 2016

server-52-85-131-115.iad53.r.cloudfront.net
June 28, 2016

server-52-85-131-113.iad53.r.cloudfront.net
June 28, 2016

server-52-85-131-84.iad53.r.cloudfront.net
June 28, 2016

server-52-85-131-76.iad53.r.cloudfront.net
June 28, 2016

server-52-85-131-51.iad53.r.cloudfront.net
June 28, 2016

server-52-85-131-150.iad53.r.cloudfront.net
June 28, 2016

server-52-85-131-119.iad53.r.cloudfront.net
June 28, 2016

server-52-85-131-118.iad53.r.cloudfront.net
June 28, 2016

server-54-192-195-36.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-9.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-232.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-222.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-176.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-120.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-78.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-61.iad53.r.cloudfront.net
February 8, 2016

File downloads found at URLs served by files.7zip.me.

2 / 68      (false positives)

1 / 68      (PUP)
http://files.7zip.me/.../7zip-en-setup.exe  (e56a3ec62bb9a934933d8887bfa4ca80)

1 / 68      (Adware)
http://files.7zip.me/.../7zip-en-setup.exe  (ee67206915de0339326935ac05fe2cc3)

The following 143 files have been seen to comunicate with files.7zip.me in live environments.

 
Latest 20 of 213 files

URL:
http://files.7zip.me/

Network:
Amazon Cloudfront

Web server:
AmazonS3