download-is.chip.eu

NOT DISCLOSED!  (Proxy Registrant)

Domain Information

The domain download-is.chip.eu is registered by proxy through Key-Systems GmbH. The domain hosts various software downloads. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Remove Malware from download-is.chip.eu - Powered by Reason Core Security
Registrar:
Key-Systems GmbH

Server location:
Oregon, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (88% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ISfreemium.b, PUP.Installer.ExtendedSetup.e, PUP.ExtendedSetup.g, PUP.ExtendedSetup.h, PUP.ExtendedSetup.EE, PUP.ExtendedSetup.i, PUP.ExtendedSetup.DD, PUP.ExtendedSetup.o, PUP.WorldSetup.e, PUP.WorldSetup.k, PUP.WorldSetup.m, PUP.WorldSetup.v, PUP.Installer.WorldSetup.d, PUP.ExtendedSetup.e, PUP.WorldSetup.W, PUP.WorldSetup.EE, PUP.WorldSetup.a, PUP.WorldSetup.g, PUP.Installer.WorldSetup.b, PUP.WorldSetup.s, PUP.WorldSetup.i, PUP.WorldSetup.DD, PUP.WorldSetup.o, PUP.ISfreemium.n, PUP.WorldSetup.AA, PUP.ExtendedSetup.CC, PUP.ISfreemium.BB, PUP.ExtendedSetup.Z, PUP.Installer.WorldSetup.h, PUP.installCore.WorldSetup (M)
94.74%

Dr.Web
Trojan.Packed.24524
94.74%

VIPRE Antivirus
InstallCore, Trojan.Win32.Generic
94.74%

Avira AntiVirus
ADWARE/InstallCore.Gen7
94.74%

Sophos
Install Core Click run software
94.74%

Vba32 AntiVirus
Downware.InstallCore
94.74%

ESET NOD32
Win32/InstallCore.FH, Win32/InstallCore.IJ (variant), Win32/InstallCore.IO (variant), Win32/InstallCore.CH (variant)
81.58%

Agnitum Outpost
PUA.InstallCore
81.58%

AVG
MalSign.InstallC, MalSign.Generic, MalSign.InstallCore
81.58%

Malwarebytes
PUP.Optional.Freemium.A, PUP.Optional.InstallCore.A
71.05%

K7 Gateway Antivirus
Unwanted-Program
71.05%

K7 AntiVirus
Unwanted-Program
68.42%

Comodo Security
Application.Win32.Installcore.BB, Application.Win32.InstallCore.AE
63.16%

Antiy Labs AVL
Trojan/Win32.SGeneric, Trojan/Win32.Tgenic
63.16%

G Data
Win32.Application.InstallCore
60.53%

The domain download-is.chip.eu has been seen to resolve to the following IP address.

ec2-50-112-97-171.us-west-2.compute.amazonaws.com
December 18, 2013

File downloads found at URLs served by download-is.chip.eu.

1 / 68      (Adware)
http://download-is.chip.eu/.../index.php?cid=136971  (utorrent3.3.2b30488 - chip downloader.exe)

17 / 68    (PUP)
http://download-is.chip.eu/.../index.php?cid=180745638  (teamspeak3-client-win64-3.0.8.1_master - chip downloader.exe)

23 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=2114064  (pfcsetup_1.0.296_master - chip downloader.exe)

13 / 68    (Adware)

14 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=100716  (ss6.11.0.102 - chip downloader.exe)

11 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=41948  (powerdvd13 - CHIP Downloader.exe)

18 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=176937  (hpu_v2.2.3 - chip downloader.exe)

18 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=109894163  (bluest0.8.4.3036_beta - chip downloader.exe)

13 / 68    (PUP)
http://download-is.chip.eu/.../index.php?cid=169658350  (lnotes1.3.dmg - chip downloader.exe)

14 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=1599250  (pcsuite_for_iphone_v2.9.63.276 - CHIP Downloader.exe)

18 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=108599  (BitTorrent-7.6-build-26764_RO - CHIP Downloader.exe)

18 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=136974  (utorrent_RO - CHIP Downloader.exe)

17 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=579862  (SumatraPDF_v2.4_install - CHIP Downloader.exe)

18 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=27663  (archpr.450.zip - CHIP Downloader.exe)

18 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=118916  (TrojanRemover6.8.4.2606 - CHIP Downloader.exe)

18 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=1614501  (VirtualDubPortable1.9.11English.paf - CHIP Downloader.exe)

18 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=691294  (GIMP_portable_2.8.10 - CHIP Downloader.exe)

18 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=3742141  (pdf2wordsetup1.1 - CHIP Downloader.exe)

18 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=4991059  (VirtualPC61RC1_en.zip - CHIP Downloader.exe)

17 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=8174878  (DRPSu_12_download.chip.eu.rar - CHIP Downloader.exe)

17 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=1001409  (aaalogo2009.zip - CHIP Downloader.exe)

18 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=535244  (sdc242-32_RO - CHIP Downloader.exe)

17 / 68    (Adware)

11 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=4929951  (driverchecker273hu - chip downloader.exe)

17 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=324228  (TVersitySetup_1.9.3. - CHIP Downloader.exe)

17 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=228502  (SysinternalsSuite_download.chip.eu.zip - CHIP Downloader.exe)

17 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=181020473  (AI_Suite_II_Win7_Z10215.zip - CHIP Downloader.exe)

17 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=1186422  (soundbase_2010.11.25 - CHIP Downloader.exe)

17 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=1064159  (Google_Updater_2.4.1808_en - CHIP Downloader.exe)

14 / 68    (Adware)
http://download-is.chip.eu/.../index.php?cid=8015789  (winx-wmv-to-avi205 - chip downloader.exe)

 
Latest 30 of 43 download URLs

URL:
http://download-is.chip.eu/

Title:
“Access Denied”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Microsoft-IIS/8.5 (PHP/5.3.13)

Remove Malware from download-is.chip.eu - Powered by Reason Core Security