get.whitesmoke.com

WhiteSmoke, Inc

Domain Information

The domain get.whitesmoke.com registered by WhiteSmoke, Inc was initially registered in June of 2001 through TIERRANET INC. D/B/A DOMAINDISCOVER. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Remove Malware from get.whitesmoke.com - Powered by Reason Core Security
Registrar:
TIERRANET INC. D/B/A DOMAINDISCOVER

Server location:
Oregon, United States (US)

Create date:
Tuesday, June 19, 2001

Expires date:
Tuesday, June 19, 2018

Updated date:
Wednesday, June 19, 2013

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (93% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/WhiteSmoke (variant), Win32/InstallCore (variant), Win32/InstallCore.LG (variant), Win32/OpenCandy, Win32/TrojanDownloader.Whizelown (variant)
85.71%

Reason Heuristics
PUP.WhiteSmoke.AA, PUP.Installer.WhiteSmoke.Y, PUP.Installer.WhiteSmoke.T, PUP.WhiteSmoke.X, PUP.WhiteSmoke.V, PUP.WhiteSmoke.K, PUP.WhiteSmoke.Installer (M)
85.71%

avast!
Win32:WhiteSmoke-A [PUP], Win32:InstallCore-BA [PUP], Win32:Dropper-gen [Drp], Win32:PUP-gen [PUP]
64.29%

Comodo Security
Heur.Suspicious, Application.Win32.InstallCore.BWAN, ApplicUnwnt.Win32.Adware.WhiteSmoke.dy01
50.00%

Dr.Web
Adware.InstallCore.3, Trojan.MulDrop5.10078, Trojan.DownLoader3.37078, Adware.Conduit.6, Adware.WhiteSmoke.3
50.00%

VIPRE Antivirus
Trojan.Win32.Generic, WhiteSmoke (not malicious), Conduit
42.86%

Avira AntiVirus
Adware/WhiteSmoke.B.30, ADWARE/InstallCore.Gen, ADWARE/Adware.Gen
35.71%

Jiangmin
Trojan/Menti.pcq, Trojan/JmGeneric.aee, AdWare/WhiteSmoke.m
35.71%

McAfee
Artemis!67DEFB077C02, Generic.tra!b, Artemis!09A9E5B98BB5, Artemis!1EE1EFEC5A98, Artemis!C3C8B942131E
35.71%

McAfee Web Gateway
Artemis!67DEFB077C02, Generic.tra!b, Artemis!09A9E5B98BB5, Artemis!1EE1EFEC5A98, Heuristic.BehavesLike.Win32.ModifiedUPX.C
35.71%

ViRobot
Trojan.Win32.A.Agent.530256[UPX]
28.57%

F-Prot
W32/InstallCore.I.gen, W32/WhiteSmoke.C.gen
28.57%

Norman
W32/WhiteSmoke.M, Suspicious_Gen2.RSSKH, Downloader.BXUB
21.43%

Sophos
Install Core Installer
21.43%

Malwarebytes
Adware.Agent, PUP.Optional.Conduit.A
21.43%

The domain get.whitesmoke.com has been seen to resolve to the following 5 IP addresses.

ec2-52-11-63-189.us-west-2.compute.amazonaws.com
February 10, 2016

ec2-54-149-49-23.us-west-2.compute.amazonaws.com
February 10, 2016

ec2-54-186-136-182.us-west-2.compute.amazonaws.com
January 3, 2016

ec2-54-191-109-151.us-west-2.compute.amazonaws.com
January 3, 2016

December 29, 2013

File downloads found at URLs served by get.whitesmoke.com.

1 / 68      (Adware)
http://get.whitesmoke.com/whitesmoke_install.exe  (12060662a35c6e0bcb47284cd851ad98)

6 / 68      (Adware)

31 / 68    (PUP)

2 / 68      (Adware)

16 / 68    (PUP)

2 / 68      (Adware)

3 / 68      (Adware)
http://get.whitesmoke.com/WhiteSmokeWriterPro.exe  (83360ea3da66866a7c681953b585e53d)

15 / 68    (Adware)

2 / 68      (Adware)

2 / 68      (Adware)

15 / 68    (Adware)

2 / 68      (Adware)
http://get.whitesmoke.com/WhiteSmokeWriterTrial.exe  (ab390ac492056f5d672d578045e6930d)

2 / 68      (Adware)
http://get.whitesmoke.com/index.html  (whitesmokewritertrial.exe)

2 / 68      (Adware)

0 / 68

0 / 68

0 / 68

12 / 68    (Adware)

3 / 68      (Adware)
http://get.whitesmoke.com/WhiteSmoke_Enrichment_Full.exe  (b861ef33fc320e5f96d7f996f360c24e)

URL:
http://get.whitesmoke.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Apache

Compete.com:
US visitors:  613

Statistics are for the previous month.

Remove Malware from get.whitesmoke.com - Powered by Reason Core Security