9sxzz.download.lawyerclam.eu

NOT DISCLOSED!  (Proxy Registrant)

Domain Information

The domain 9sxzz.download.lawyerclam.eu is registered by proxy through Internet.bs Corp.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
Internet.bs Corp.

Server location:
Virginia, United States (US)

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.PluginUpdateSL.O
100.00%

Dr.Web
Trojan.DownLoader11.27075, Trojan.DownLoader11.30734
100.00%

VIPRE Antivirus
Threat.4783235, Threat.4150696
100.00%

MicroWorld eScan
Gen:Variant.Strictor.61140, Application.Bundler.DomaIQ.T
100.00%

McAfee
Socrydo
100.00%

K7 AntiVirus
Unwanted-Program
100.00%

Bitdefender
Gen:Variant.Strictor.61140, Application.Bundler.DomaIQ.T
100.00%

Emsisoft Anti-Malware
Gen:Variant.Strictor.61140, Application.Bundler.DomaIQ.T
100.00%

F-Secure
Gen:Variant.Strictor.61140, Application.Bundler.DomaIQ
100.00%

Avira AntiVirus
TR/Dropper.Gen, APPL/Softpulse.Gen8
100.00%

Sophos
SoftPulse
100.00%

AhnLab V3 Security
PUP/Win32.DomaIQ, Win-Trojan/Inject.1526984
100.00%

G Data
Gen:Variant.Strictor.61140, Application.Bundler.DomaIQ
100.00%

AVG
Found Win32/DH{gRJ UIEHeVRPFVGBFYEJHFOBE0GBDw}
100.00%

Panda Antivirus
Trj/Genetic.gen
100.00%

The domain 9sxzz.download.lawyerclam.eu has been seen to resolve to the following 2 IP addresses.

ec2-184-73-247-179.compute-1.amazonaws.com
August 17, 2014

208.43.10.6-static.reverse.softlayer.com
August 17, 2014

File downloads found at URLs served by 9sxzz.download.lawyerclam.eu.

URL:
http://9sxzz.download.lawyerclam.eu/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Microsoft-IIS/7.5 (ASP.NET)