Server location:
Washington, United States (US)
ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US
Scanner detections:
Malware distribution (80% detected)
Scan engine
Details
Detections
ESET NOD32
Win32/InstallCore.ACY.gen potentially unwanted application, Win32/InstallCore.AFY potentially unwanted application, Win32/Sality.NAU virus
80.00%
Dr.Web
Trojan.InstallCore.978, Adware.InstallCore.653, Win32.Sector.12, Win32.Sector.30
80.00%
McAfee
Artemis!0756591F5975, Artemis!01F7F52C5EE3, Virus.W32/Sality.gen.z
80.00%
avast!
Win32:Malware-gen, Win32:Kukacka, Win32:SaliCode
60.00%
AhnLab V3 Security
PUP/Win32.Downloader
60.00%
VIPRE Antivirus
Trojan.Win32.Generic, Threat.416209
40.00%
Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
40.00%
Reason Heuristics
Adware.Bundler (M)
40.00%
F-Prot
W32/Sality.AK, W32/Sality.gen2
40.00%
Microsoft Security Essentials
Threat.Undefined
40.00%
Emsisoft Anti-Malware
Win32.Sality.OG
40.00%
Norman
Win32.Sality.OG, Win32.Sality.3
40.00%
AegisLab AV Signature
Suspicious.Cloud.Gen!c
20.00%
Agnitum Outpost
PUA.InstallCore
20.00%
The domain www.bulkbundlescity.com has been seen to resolve to the following 18 IP addresses.
server-52-85-131-245.iad53.r.cloudfront.net
July 4, 2016
server-52-85-131-233.iad53.r.cloudfront.net
July 4, 2016
server-52-85-131-232.iad53.r.cloudfront.net
July 4, 2016
server-52-85-131-141.iad53.r.cloudfront.net
July 4, 2016
server-52-85-131-127.iad53.r.cloudfront.net
July 4, 2016
server-52-85-131-104.iad53.r.cloudfront.net
July 4, 2016
server-52-85-131-56.iad53.r.cloudfront.net
July 4, 2016
server-52-85-131-22.iad53.r.cloudfront.net
July 4, 2016
server-52-85-131-171.iad53.r.cloudfront.net
April 21, 2016
server-52-85-131-30.iad53.r.cloudfront.net
April 12, 2016
server-52-85-131-206.iad53.r.cloudfront.net
April 10, 2016
server-52-85-131-196.iad53.r.cloudfront.net
April 10, 2016
server-52-85-131-167.iad53.r.cloudfront.net
April 10, 2016
server-52-85-131-155.iad53.r.cloudfront.net
April 10, 2016
server-52-85-131-114.iad53.r.cloudfront.net
April 10, 2016
server-52-85-131-51.iad53.r.cloudfront.net
April 10, 2016
server-52-85-131-239.iad53.r.cloudfront.net
April 10, 2016
server-52-85-131-235.iad53.r.cloudfront.net
April 10, 2016
File downloads found at URLs served by www.bulkbundlescity.com.
The following 3 files have been seen to comunicate with www.bulkbundlescity.com in live environments.