www.dmefree.com

PC SOLUTIONS SOFTWARE DEV

Domain Information

The domain www.dmefree.com registered by PC SOLUTIONS SOFTWARE DEV was initially registered in August of 2000 through 1&1 INTERNET SE. Currently this domain has been known to host various forms of malware. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
1&1 INTERNET SE

Server location:
Virginia, United States (US)

Create date:
Monday, August 28, 2000

Expires date:
Sunday, August 28, 2016

Updated date:
Thursday, February 11, 2016

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Quick Heal
(Suspicious) - DNAScan
100.00%

McAfee
RDN/Generic.dx!d2f
100.00%

K7 AntiVirus
Riskware
100.00%

Norman
Malware.AJRIN
100.00%

avast!
Win32:Malware-gen
100.00%

Kaspersky
UDS:DangerousObject.Multi.Generic
100.00%

Dr.Web
Trojan.DownLoader9.48219
100.00%

Qihoo 360 Security
Win32/Trojan.Multi.daf
100.00%

The domain www.dmefree.com has been seen to resolve to the following 4 IP addresses.

ec2-52-72-80-1.compute-1.amazonaws.com
May 22, 2016

ec2-52-5-129-147.compute-1.amazonaws.com
May 22, 2016

ec2-52-2-172-163.compute-1.amazonaws.com
May 22, 2016

ec2-54-85-150-195.compute-1.amazonaws.com
May 22, 2016

File downloads found at URLs served by www.dmefree.com.

8 / 68      (Malware)
http://www.dmefree.com/.../dmefreeremote.exe  (f95ca9b0b8026bca9dea8ee19b81a36d)

The following file have been seen to comunicate with www.dmefree.com in live environments.

URL:
http://www.dmefree.com/

Google Analytics:
UA-2117194

Title:
“DME Billing Software from DMEFree SimpleClaims Affordable Medicare”

Description:
“DME Billing Software from DMEFree and Simpleclaims Medical billing by PC Solutions, Medicaid, Medicare DMERC HME DME Software Commercial Billing”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Pepyaka/1.9.13

30 of 56 related domains