cld3r.com

John Smith

Domain Information

The domain cld3r.com registered by John Smith was initially registered in August of 2013 through KEY-SYSTEMS GMBH. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Remove Malware from cld3r.com - Powered by Reason Core Security
Registrar:
KEY-SYSTEMS GMBH

Server location:
Dublin City, Ireland (IE)

Create date:
Tuesday, August 27, 2013

Expires date:
Saturday, August 27, 2016

Updated date:
Thursday, August 13, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.PaymentsInteractiveSL.M, PUP.Installer.ClovermediaSL.M, PUP.Installer.PluginUpdateSL.M, PUP.Installer.DigitalPluginSL.M, PUP.Outbrowse.StartNow, PUP.Outbrowse.StartNow.Bundler (M), PUP.Softpulse.SmartSecuresoftware.Bundler (M), PUP.Tuguu.PaymentsInteractive.Bundler (M)
100.00%

McAfee
Adware-DomaIQ!35F73A919572, Adware-DomaIQ!23E7BC0FA157, Artemis!A568391114B9, Artemis!D4A17461270E, Program.CryptDomaIQ
52.38%

Malwarebytes
PUP.Optional.BundleInstaller.A, PUP.Optional.DomaIQ, PUP.Optional.OutBrowse
52.38%

VIPRE Antivirus
DomaIQ, Threat.4150696
52.38%

Dr.Web
Trojan.DownLoader9.62498, Trojan.DownLoader11.4884, Adware.Downware.2630, Adware.Downware.4620, Trojan.DownLoader11.29457
52.38%

Avira AntiVirus
APPL/DomaIQ.Gen, APPL/Bundler.DomaIQ.3, Adware/Lollipop.708544, APPL/Downloader.Gen8, Adware/Softpulse.107390, APPL/Outbrowse.Gen
52.38%

AVG
DomaIQ, Adware DomaIQ.CI, Adware DomaIQ.EZ, Generic, Potentially harmful program Downloader.CHY, Potentially harmful program Downloader.CER
52.38%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious.H, Artemis!D4A17461270E, CryptDomaIQ, SoftPulse, BehavesLike.Win32.MPlug.tc, BehavesLike.Win32.CryptDoma.hc
47.62%

Agnitum Outpost
PUA.Lollipop, PUA.DomaIQ, PUA.Agent, Riskware.Agent, PUA.OutBrowse
42.86%

G Data
Gen:Variant.Application.Bundler.DomaIQ, Adware.DomaIQ.AO, Gen:Variant.Application.Bundler.DomaIQ.10, Win32.Trojan-Downloader.Lisp
42.86%

avast!
DomaIQ-CC [PUP], DomaIQ-CO [PUP], Win32:Agent-AUBR [PUP], Win32:SoftPulse-AH [PUP], OutBrowse-AI [PUP], OutBrowse-AJ [PUP]
42.86%

AhnLab V3 Security
PUP/Win32.DomaIQ, PUP/Win32.OutBrowse
42.86%

MicroWorld eScan
Gen:Variant.Application.Bundler.DomaIQ.3, Adware.DomaIQ.AO, Gen:Variant.Application.Bundler.DomaIQ.10, Application.Bundler.DomaIQ.Q
38.10%

K7 Gateway Antivirus
Unwanted-Program
38.10%

K7 AntiVirus
Unwanted-Program
38.10%

The domain cld3r.com has been seen to resolve to the following 3 IP addresses.

ec2-54-194-150-74.eu-west-1.compute.amazonaws.com
June 20, 2014

May 10, 2014

ec2-54-194-139-2.eu-west-1.compute.amazonaws.com
May 10, 2014

File downloads found at URLs served by cld3r.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

15 / 68    (Adware)

18 / 68    (Adware)

32 / 68    (Adware)

25 / 68    (Adware)

25 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

34 / 68    (Adware)

34 / 68    (Adware)

32 / 68    (Adware)

28 / 68    (Adware)

24 / 68    (Adware)

26 / 68    (Adware)

URL:
http://cld3r.com/

Title:
“Get ready to have sex tonight!”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx/1.6.3 (HHVM/3.8.0-dev)

Remove Malware from cld3r.com - Powered by Reason Core Security