files.red-9-small-button.com

Whois Privacy Corp.

Domain Information

The domain files.red-9-small-button.com registered by Whois Privacy Corp. was initially registered in February of 2015 through TLD REGISTRAR SOLUTIONS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network.
Registrar:
TLD REGISTRAR SOLUTIONS LTD

Server location:
Dublin City, Ireland (IE)

Create date:
Wednesday, February 4, 2015

Expires date:
Saturday, February 4, 2017

Updated date:
Friday, February 5, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (54% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Amonitize.BERSHNET (M)
71.43%

Kaspersky
not-a-virus:Downloader.Win32.Agent
28.57%

Emsisoft Anti-Malware
Gen:Variant.Adware.Kazy.597398, Gen:Variant.Application.Jatif.320
28.57%

Lavasoft Ad-Aware
Gen:Variant.Adware.Kazy.597398, Gen:Variant.Application.Jatif.320
28.57%

Dr.Web
infected with Trojan.Amonetize
28.57%

ESET NOD32
Win32/Amonetize.DW potentially unwanted application
28.57%

Norman
Gen:Variant.Adware.Kazy.597398, Gen:Variant.Application.Jatif.320
28.57%

Sophos
PUA 'Amonetize'
28.57%

MicroWorld eScan
Gen:Variant.Adware.Kazy.597398, Gen:Variant.Application.Jatif.320
28.57%

Quick Heal
PUA.Bershnetll.Gen
28.57%

McAfee
Artemis!2240D186899E, Artemis!98453425C56F
28.57%

Arcabit
Trojan.Adware.Kazy.D91D96, Trojan.Application.Jatif.320
28.57%

NANO AntiVirus
Trojan.Win32.Agent.dunutq, Trojan.Win32.Agent.durdcp
28.57%

F-Prot
W32/S-53544127
28.57%

Trend Micro House Call
TROJ_GE.5E6B3F2A, TROJ_GE.4EDFE45C
28.57%

The domain files.red-9-small-button.com has been seen to resolve to the following 2 IP addresses.

May 20, 2016

ns1.ibspark.com
February 13, 2016

File downloads found at URLs served by files.red-9-small-button.com.

1 / 68      (Adware)

0 / 68
http://files.red-9-small-button.com/p/.../Process L o Pro 8.6.1.6.ArabSeeD.CoM.rar_10924_i38460761_il345.exe  (process+l+o+pro+8.6.1.6.arabseed.com.rar_10924_i38460761_il345.exe.zip)

1 / 68      (Adware)

0 / 68

0 / 68
http://files.red-9-small-button.com/p/.../assassins creed rogue update v1 1 0 and crack_10924_i39035818_il345.exe  (assassins+creed+rogue+update+v1+1+0+and+crack_10924_i39035818_il345.exe.zip)

1 / 68      (Adware)

27 / 68    (PUP)
http://files.red-9-small-button.com/p/.../Printable Academic Calendar 2015 16_10924_i38725293_il345.exe  (printable+academic+calendar+2015+16_10924_i38725293_il345.exe.zip)

26 / 68    (PUP)

The following 142 files have been seen to comunicate with files.red-9-small-button.com in live environments.

 
Latest 20 of 155 files

URL:
http://files.red-9-small-button.com/

Google Analytics:
UA-48689684

Title:
“red-9-small-button.com”

Web server:
nginx

30 of 618 related domains