ttb.lpmxp2182.com
Only contact by email, all postal mail will be rejected (Proxy Registrant)
Domain Information
The domain ttb.lpmxp2182.com is registered by proxy through SOLUCIONES CORPORATIVAS IP,SLU and was originally registered in September of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrant:
Only contact by email, all postal mail will be rejected
Registrar:
SOLUCIONES CORPORATIVAS IP,SLU
Server location:
Oregon, United States (US)
Create date:
Thursday, September 18, 2014
Expires date:
Friday, September 18, 2015
Updated date:
Thursday, September 18, 2014
ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.DigitalPluginSL.F, PUP.Softpulse.DigitalPlugin.Bundler (M), Win32.Generic, PUP.Softpulse.DigitalP.Bundler (M), Threat.Win.Reputation.IMP
93.75%
avast!
Win32:SoftPulse-AH [PUP], Win32:GenMalicious-ADB [PUP]
18.75%
AVG
Generic, Adware AdPlugin.DXU
18.75%
Dr.Web
Trojan.MulDrop5.40191
12.50%
VIPRE Antivirus
Threat.4150696
12.50%
K7 AntiVirus
Unwanted-Program
12.50%
G Data
Application.Bundler.DomaIQ, Win32.Application.Softpulse
12.50%
Vba32 AntiVirus
BScope.Adware.Softpulse
12.50%
herdProtect (fuzzy)
a variant of 0aaa1ea245f983cd862b86964b889bf7da055e16, a variant of 506fdf7a08a57952b86f58c6d4eea7f0ed7155ea
12.50%
Kaspersky
not-a-virus:Downloader.Win32.LMN
12.50%
Malwarebytes
PUP.Optional.MultiPlug
12.50%
Zillya! Antivirus
Adware.Agent.Win32.13299
12.50%
NANO AntiVirus
Trojan.Win32.Agent.dfjvlg
12.50%
The domain ttb.lpmxp2182.com has been seen to resolve to the following 2 IP addresses.
ec2-54-69-147-88.us-west-2.compute.amazonaws.com
September 30, 2014
ec2-54-187-228-136.us-west-2.compute.amazonaws.com
September 27, 2014
File downloads found at URLs served by ttb.lpmxp2182.com.
URL:
http://ttb.lpmxp2182.com/
Network:
Amazon Web Services (AWS), running an EC2 instance
Web server:
nginx (PHP/5.3.10-1ubuntu3.11)