www.tourvaultdelivery.com

Domain Information

Server location:
Virginia, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.installCore (M)
66.67%

ESET NOD32
Win32/FusionCore.E potentially unwanted application
33.33%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.DealPly
33.33%

The domain www.tourvaultdelivery.com has been seen to resolve to the following 24 IP addresses.

server-54-230-102-29.iad2.r.cloudfront.net
April 12, 2016

server-54-230-102-201.iad2.r.cloudfront.net
April 12, 2016

server-54-230-102-171.iad2.r.cloudfront.net
April 12, 2016

server-54-230-102-103.iad2.r.cloudfront.net
April 12, 2016

server-54-230-102-96.iad2.r.cloudfront.net
April 12, 2016

server-54-230-102-94.iad2.r.cloudfront.net
April 12, 2016

server-54-230-102-42.iad2.r.cloudfront.net
April 12, 2016

server-54-230-102-37.iad2.r.cloudfront.net
April 12, 2016

server-52-85-131-117.iad53.r.cloudfront.net
April 6, 2016

server-52-85-131-110.iad53.r.cloudfront.net
April 6, 2016

server-52-85-131-53.iad53.r.cloudfront.net
April 6, 2016

server-52-85-131-251.iad53.r.cloudfront.net
April 6, 2016

server-52-85-131-202.iad53.r.cloudfront.net
April 6, 2016

server-52-85-131-177.iad53.r.cloudfront.net
April 6, 2016

server-52-85-131-151.iad53.r.cloudfront.net
April 6, 2016

server-52-85-131-138.iad53.r.cloudfront.net
April 6, 2016

server-54-240-160-85.iad12.r.cloudfront.net
February 1, 2016

server-54-240-160-77.iad12.r.cloudfront.net
February 1, 2016

server-54-240-160-71.iad12.r.cloudfront.net
February 1, 2016

server-54-240-160-39.iad12.r.cloudfront.net
February 1, 2016

server-54-240-160-26.iad12.r.cloudfront.net
February 1, 2016

server-54-240-160-195.iad12.r.cloudfront.net
February 1, 2016

server-54-240-160-184.iad12.r.cloudfront.net
February 1, 2016

server-54-240-160-114.iad12.r.cloudfront.net
February 1, 2016

File downloads found at URLs served by www.tourvaultdelivery.com.

1 / 68      (PUP)
http://www.tourvaultdelivery.com/.../installer.exe  (2defcc8d476c5cf0de281de75697f9f7)

1 / 68      (PUP)
http://www.tourvaultdelivery.com/.../installer.exe  (367b125e1c93807b9a226bde1fd9b91d)

2 / 68      (PUP)
http://www.tourvaultdelivery.com/.../installer.exe  (6e5918d4400a5cf35b52a441b833adbb)

The following file have been seen to comunicate with www.tourvaultdelivery.com in live environments.