The domain dlp.cloudsvr300.com is registered by proxy through SOLUCIONES CORPORATIVAS IP,SLU and was originally registered in November of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Vitoria-Gasteiz, Pais Vasco within Spain which resides on the RIPE Network Coordination Centre network.
SOLUCIONES CORPORATIVAS IP,SLU
Pais Vasco, Spain (ES)
Sunday, November 24, 2013
Tuesday, November 24, 2015
Wednesday, November 26, 2014
AS57910 SCIP-AS Soluciones Corporativas IP, SL,ES
Detections (96% detected)
PUP.Installer.TuguuIsrael.M, PUP.Installer.BundloreLimited.F, PUP.Installer.TuguuIsrael.I, PUP.Installer.TuguuIsrael.F, PUP.TuguuIsrael.M, PUP.Installer.TUGUUSL.F, PUP.Installer.InstallationSafe.F, PUP.Tuguu.TuguuIsrael.Bundler (M)
W32/Sality.AT, APPL/DomaIQ.Gen2, SPR/Bundlore.A, APPL/DomaIQ.G.2
PUP.Optional.BundleInstaller.A, PUP.Optional.Bundlore, PUP.Optional.DomaIQ
DomainIQ pay-per install, Bundlore, Generic PUA IP, PUA 'DomainIQ pay-per install'
DomaIQ, Bundlore, Threat.4150696, Threat.4783235, Threat.4783262
McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious.D, Artemis!7FA7B38A12E2, Artemis!564F55A8164A, Heuristic.BehavesLike.Win32.Suspicious.H
Skodna.Generic_r, MalSign.Bundlo, DomaIQ_r.H, Adware Skodna.Generic_r.HZ, Adware Skodna.Generic_r.IA, Adware DomaIQ.AN
Adware-DomaIQ!38AEEDFECC37, Artemis!7FA7B38A12E2, Artemis!564F55A8164A, Adware-DomaIQ!B128DAD6C959, CryptDomaIQ, Program.CryptDomaIQ
K7 Gateway Antivirus
Unwanted-Program , Trojan
not-a-virus:AdWare.MSIL.DomaIQ, not-a-virus:AdWare.Win32.Lollipop, HEUR:Trojan.Win32.Generic
Application.Win32.Agent.D, Application.Win32.Bundlore.A, Application.Win32.DomaIQ.PUP, Application.Win32.DomaIQ.D
AdWare/MSIL.acc, Pack.Mal.AntiVM, AdWare/MSIL.akt, AdWare/MSIL.afq
PUP/MultiToolbar.A, Generic Malware
Trojan , Unwanted-Program
MSIL/DomaIQ, Win32/Bundlore (variant), MSIL/DomaIQ (variant), Win32/DomaIQ.BB (variant)
The domain dlp.cloudsvr300.com has been seen to resolve to the following 9 IP addresses.
May 3, 2015
December 1, 2014
File downloads found at URLs served by dlp.cloudsvr300.com.
The following 138 files have been seen to comunicate with dlp.cloudsvr300.com in live environments.
30 of 100 related domains