ttb.defiletake.com
WHOIS PRIVACY PROTECTION SERVICE, INC. (Proxy Registrant)
Domain Information
The domain ttb.defiletake.com is registered by proxy through ENOM, INC. and was originally registered in June of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Beaumaris, Victoria within Australia which resides on the Asia Pacific Network Information Centre network.
Registrant:
WHOIS PRIVACY PROTECTION SERVICE, INC.
Server location:
Victoria, Australia (AU)
Create date:
Monday, June 1, 2015
Expires date:
Wednesday, June 1, 2016
Updated date:
Monday, June 1, 2015
ASN:
AS133618 TRELLIAN-AS-AP Trellian Pty. Limited,AU
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Softpulse.PLUGINUPDATE.Bundler (M), PUP.Softpulse.PLUGINUP.Bundler (M), PUP.Softpulse (M)
100.00%
The domain ttb.defiletake.com has been seen to resolve to the following 5 IP addresses.
lb-182-241.above.com
September 16, 2016
ec2-54-69-125-213.us-west-2.compute.amazonaws.com
January 27, 2016
ec2-54-191-36-84.us-west-2.compute.amazonaws.com
January 27, 2016
File downloads found at URLs served by ttb.defiletake.com.
Latest 30 of 71 download URLs
The following 13 files have been seen to comunicate with ttb.defiletake.com in live environments.
URL:
http://ttb.defiletake.com/
Web server:
nginx (PHP/5.3.10-1ubuntu3.17)