cdnus.ironcdn.com

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain cdnus.ironcdn.com is registered by proxy through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM and was originally registered in March of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Frankfurt Am Main, Hessen within Germany which resides on the Leaseweb USA, Inc. network.
Remove Malware from cdnus.ironcdn.com - Powered by Reason Core Security
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Hessen, Germany (DE)

Create date:
Wednesday, March 28, 2012

Expires date:
Monday, March 28, 2016

Updated date:
Tuesday, February 24, 2015

ASN:
AS30633 LEASEWEB-US - Leaseweb USA, Inc.

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Dr.Web
Win32.Sector.21, Adware.InstallCore.80, Adware.InstallCore.55, Adware.InstallCore.72, Adware.InstallCore.53
100.00%

Avira AntiVirus
W32/Sality.AT, ADWARE/InstallCore.Gen
98.00%

F-Prot
W32/Sality.gen2, W32/InstallCore.S.gen, W32/InstallCore.S2.gen, W32/InstallCore.W.gen, W32/InstallCore.W2.gen, W32/InstallCore.G.gen, W32/InstallCore.P.gen
98.00%

ESET NOD32
Win32/InstallCore.AZ (variant), Win32/InstallCore.AF (variant), Win32/InstallCore.AY (variant), Win32/InstallCore.AW (variant)
96.00%

Trend Micro House Call
TROJ_GEN.RCBH1CC, TROJ_GEN.RCBH1CH, TROJ_GEN.RCBH1CO, TROJ_GEN.RCBH1CB, TROJ_GEN.F47V1223, TROJ_GEN.F47V0115, TROJ_GEN.F47V0103, TROJ_GEN.F47V1227, TROJ_GEN.RCBH1LM, TROJ_GEN.RCBH1AM
94.00%

K7 AntiVirus
Unwanted-Program, Unwanted-Program , Riskware, Trojan
90.00%

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
90.00%

Malwarebytes
PUP.Optional.InstallCore
90.00%

AhnLab V3 Security
PUP/Win32.InstallCore, Packed/Win32.InstallCore, ASD.Prevention, Adware/Win32.InstallCore
88.00%

Sophos
InstallCore ToDownload, Generic PUA JL, Install Core
88.00%

Reason Heuristics
PUP.NextRadioTV.h, PUP.NextRadioTV.N, PUP.NextRadioTV.I, PUP.NextRadioTV.FF, PUP.NextRadioTV.O, PUP.NextRadioTV.G, PUP.NextRadioTV.R
86.00%

Comodo Security
ApplicUnwnt.Win32.AdWare.Agent.~A, UnclassifiedMalware, Application.Win32.InstallCore.~A
86.00%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud), Win32.Troj.Agent.ac.(kcloud)
86.00%

Emsisoft Anti-Malware
Riskware.Win32.InstallCore.AMN, Riskware.WebToolbar.Win32.InstallCore.AMN!A2, Trojan.CryptRedol.Gen
86.00%

McAfee
Artemis!2AEFB1295F60, Artemis!56B053E5B063, Artemis!19EF503B0319, Artemis!2BA4BD2F9CEC, Artemis!AA6EA3738A18, Artemis!803C759F7457, Artemis!3DF0A845B746, Artemis!2D6FE1E4DF49
84.00%

The domain cdnus.ironcdn.com has been seen to resolve to the following 7 IP addresses.

May 6, 2015

May 6, 2015

February 6, 2014

November 16, 2013

50.115.122.45.static.westdc.net
November 16, 2013

hosted-by.leaseweb.com
November 16, 2013

hosted-by.leaseweb.com
November 16, 2013

File downloads found at URLs served by cdnus.ironcdn.com.

23 / 68    (PUP)
http://cdnus.ironcdn.com/.../Daemon-Tools-Lite.exe  (2d6fe1e4df497715bab2ec14ecb4127b)

6 / 68      (PUP)
http://cdnus.ironcdn.com/.../Picasa.exe  (735395abb88a0f7e2e7c870c7fe1efb9)

22 / 68    (PUP)
http://cdnus.ironcdn.com/.../Winrar.exe  (212bbab83f5e068fcac2a3ab91ee0a55)

6 / 68      (PUP)
http://cdnus.ironcdn.com/.../Free-Video-Converter.exe  (7eae096e847717d70f5689e0c0f1b8fc)

22 / 68    (PUP)
http://cdnus.ironcdn.com/.../7ZIP.exe  (9f94f2dced9c6b1acc6c59284463f7aa)

9 / 68      (PUP)
http://cdnus.ironcdn.com/.../Adobe-Reader-X.exe  (dc0b0bd82cff98c9e8669b99262f5457)

9 / 68      (PUP)

14 / 68    (Adware)
http://cdnus.ironcdn.com/.../Winrar-420.exe  (icreinstall_winrar-420.exe)

26 / 68    (Adware)
http://cdnus.ironcdn.com/.../Rogue-Killer.exe  (ec9c1c2adc329f48a5709f5c34bf95c1)

26 / 68    (Adware)
http://cdnus.ironcdn.com/.../SopCast.exe  (b87a715e3a96335c62860ab478e31e72)

25 / 68    (Adware)
http://cdnus.ironcdn.com/.../Adobe-Flash-Player.exe  (740af8f649b22840e5903c2702867e32)

26 / 68    (Adware)
http://cdnus.ironcdn.com/.../TeamSpeak.exe  (9a0cb6aab8fe9fb0efa4488a37b411bc)

25 / 68    (Adware)
http://cdnus.ironcdn.com/.../HTTrack.exe  (3df0a845b746371c23282b63cee38f39)

26 / 68    (Adware)
http://cdnus.ironcdn.com/.../Nokia-PC-Suite.exe  (ccf41328d7cc88c2e502770a7f92d002)

25 / 68    (Adware)
http://cdnus.ironcdn.com/.../Samsung-Kies.exe  (74865252d95a5f5cf5f99eba21fcee54)

26 / 68    (Adware)

25 / 68    (Adware)
http://cdnus.ironcdn.com/.../ITunes.exe  (55784b6097abd00cded0b3240bc9663d)

16 / 68    (Adware)
http://cdnus.ironcdn.com/.../Opera.exe  (38e489454cd3d065e3f6f33b9f0652b6)

26 / 68    (Adware)
http://cdnus.ironcdn.com/.../Visionneuse-PP-2007.exe  (ed766e4502461db58988c7fce27ee67b)

26 / 68    (Adware)
http://cdnus.ironcdn.com/.../San-Andreas-Multiplayer.exe  (01938e370994f251c7f813241fe287ac)

25 / 68    (Adware)
http://cdnus.ironcdn.com/.../Samsung-PC-Studio.exe  (803c759f7457876f0c43f6b3fabc1d0c)

26 / 68    (Adware)
http://cdnus.ironcdn.com/.../K-Lite-Codec-Pack-Full.exe  (3e70699bca9843a4b098fa2e86c12236)

25 / 68    (Adware)
http://cdnus.ironcdn.com/.../uTorrent.exe  (be8da04a0aeb97278114527fa4ea4f56)

26 / 68    (Adware)
http://cdnus.ironcdn.com/.../ADSL-TV-FM.exe  (4901111b12ef67c3029b3c09ee30a268)

26 / 68    (Adware)
http://cdnus.ironcdn.com/.../BitTorrent.exe  (2a702a6d7cd3f7ff2c88ad1359c3d2ac)

26 / 68    (Adware)

25 / 68    (Adware)
http://cdnus.ironcdn.com/.../QuickTime.exe  (bf4ce1cc75777630bfa06602697707c8)

25 / 68    (Adware)
http://cdnus.ironcdn.com/.../Real-Player.exe  (88cffb0835994b5f0bf021b4c0006d6c)

25 / 68    (Adware)
http://cdnus.ironcdn.com/.../iTunes-64b.exe  (894be7b876970d0bf3f839abdf44eb34)

8 / 68      (Adware)
http://cdnus.ironcdn.com/.../Nero11.exe  (7398e385405a067d13d1a345e9d7d5d2)

 
Latest 30 of 52 download URLs

The following 13 files have been seen to comunicate with cdnus.ironcdn.com in live environments.

URL:
http://cdnus.ironcdn.com/

Web server:
nginx/1.0.10

Remove Malware from cdnus.ironcdn.com - Powered by Reason Core Security