downloader.chip.de

Domain Information

Remove Malware from downloader.chip.de - Powered by Reason Core Security
Server location:
Bayern, Germany (DE)

ASN:
AS24940 HETZNER-AS Hetzner Online AG,DE

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP, PUP.Optional.CovusFreemiumGmbH.W, PUP.FreemiumGmbH, PUP.Covus, PUP.Bundler.Covus, Threat.Covus.Bundler, PUP.Covus.Bundler, PUP.Covus.CovusFreemiumGmbH.Bundler (M), PUP.Covus.FreemiumGmbH.Bundler (M), PUP.Covus.CovusFreemium.Bundler (M), PUP.Covus.Freemium.Bundler (M)
98.00%

AVG
Covusfreemium, Generic, DownloadAssistant.C, Could be an adware MultiBundle.dropper, Adware Generic_r.OC
64.00%

ESET NOD32
Win32/DownloadGuide.D potentially unwanted application, Win32/DownloadGuide.E potentially unwanted application, Win32/DownloadSponsor.C potentially unwanted application
56.00%

Dr.Web
Adware.Downware.9168, Adware.Downware.9662, Trojan.Packed, Adware.Downware.9749, Adware.Downware.10328, Adware.Downware.10328, Adware.Downware.9982
54.00%

NANO AntiVirus
Trojan.Win32.MLW.divivp, Trojan.Win32.DownloadGuide.dlpugq, Trojan.Win32.DownloadGuide.dmjzno, Trojan.Win32.DownloadGuide.dmsvik
46.00%

K7 Gateway Antivirus
Unwanted-Program
44.00%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic, Threat.4890059
42.00%

K7 AntiVirus
Unwanted-Program
42.00%

Avira AntiVirus
APPL/Downloader.Gen, APPL/DownloadGuide.D, PUA/DownloadGuide.C, PUA/DownloadGuide.Gen, PUA/DownloadSponsor.Gen
38.00%

Antiy Labs AVL
Trojan/Win32.TSGeneric, RiskWare[Downloader:not-a-virus]/Win32.DownloadHelper, Trojan[Downloader:not-a-virus]/Win32.DownloadHelper.a
34.00%

Kaspersky
not-a-virus:Downloader.Win32.DownloadHelper, not-a-virus:Downloader.Win32.OCSBundle, not-a-virus:Downloader.Win32.DownloaderGuide
34.00%

Bkav FE
W32.HfsAdware
34.00%

Malwarebytes
PUP.Optional.Eguide, PUP.Optional.DownloadGuide, PUP.Optional.Freemium.A, PUP.Optional.DownloadSponsor
24.00%

Agnitum Outpost
Riskware.Agent
22.00%

herdProtect (fuzzy)
a variant of 49c3be7401eba5f9e987d4125b122f6bf2c84bbd, a variant of 3e8f958eb8a315cc8f6fcf47d35caadc55c64bf4, a variant of 0d6ae1d4358d849b1792738ea4e115a6ac36b10d
22.00%

The domain downloader.chip.de has been seen to resolve to the following 4 IP addresses.

www1.thinklabs-cluster.de
May 5, 2015

www2.thinklabs-cluster.de
May 5, 2015

dstpp2.thinklabs-cluster.de
December 26, 2013

dstpp1.thinklabs-cluster.de
December 26, 2013

File downloads found at URLs served by downloader.chip.de.

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

11 / 68    (PUP)

13 / 68    (PUP)

13 / 68    (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://downloader.chip.de/thirdpartyproxy/.../downloader-covus_create.php?cid=4337937  (ati catalyst driver pro windows vista_windows 7 10.6 downloader.exe)

20 / 68    (PUP)

20 / 68    (PUP)

14 / 68    (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

7 / 68      (PUP)

7 / 68      (PUP)
http://downloader.chip.de/thirdpartyproxy/.../downloader-covus_create.php?cid=7947106  (50 самых жарких обоев 1 downloader.exe)

7 / 68      (PUP)
http://downloader.chip.de/thirdpartyproxy/.../downloader-covus_create.php?cid=9087838  (86 обоев на любой вкус downloader.exe)

7 / 68      (PUP)

6 / 68      (PUP)

11 / 68    (PUP)

9 / 68      (PUP)

17 / 68    (PUP)

8 / 68      (PUP)

 
Latest 30 of 131 download URLs

The following 6 files have been seen to comunicate with downloader.chip.de in live environments.

Remove Malware from downloader.chip.de - Powered by Reason Core Security