get.whitesmoke.com

WhiteSmoke, Inc

Domain Information

The domain get.whitesmoke.com registered by WhiteSmoke, Inc was initially registered in June of 2001 through TIERRANET INC. D/B/A DOMAINDISCOVER. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
TIERRANET INC. D/B/A DOMAINDISCOVER

Server location:
Oregon, United States (US)

Create date:
Tuesday, June 19, 2001

Expires date:
Tuesday, June 19, 2018

Updated date:
Wednesday, June 19, 2013

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc., US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.WhiteSmoke.AA, PUP.Installer.WhiteSmoke.Y, PUP.Installer.WhiteSmoke.T, (M), PUP.WhiteSmoke.X, PUP.WhiteSmoke.V, PUP.WhiteSmoke.K, PUP.WhiteSmoke.Installer (M), PUP.WhiteSmoke.InstallCoreC.Installer (M), PUP.WhiteSmoke.InstallC.Installer (M), PUP.WhiteSmoke.InstallB.Installer (M), PUP.Amonetize.Bundler (M), PUP.WhiteSmoke (M)
87.10%

ESET NOD32
Win32/WhiteSmoke (variant), Win32/InstallCore (variant), Win32/InstallCore.LG (variant), Win32/OpenCandy, Win32/TrojanDownloader.Whizelown (variant)
58.06%

avast!
Win32:WhiteSmoke-A [PUP], Win32:InstallCore-BA [PUP], Win32:Dropper-gen [Drp], Win32:PUP-gen [PUP]
41.94%

Dr.Web
Adware.InstallCore.3, Trojan.MulDrop5.10078, Trojan.DownLoader3.37078, Adware.Conduit.6, Trojan.MulDrop2.8152, Adware.WhiteSmoke.3
41.94%

Comodo Security
Heur.Suspicious, Application.Win32.InstallCore.BWAN, ApplicUnwnt.Win32.Adware.WhiteSmoke.dy01
38.71%

VIPRE Antivirus
Trojan.Win32.Generic, WhiteSmoke (not malicious), Conduit
32.26%

Avira AntiVirus
Adware/WhiteSmoke.B.30, ADWARE/InstallCore.Gen, ADWARE/Adware.Gen
29.03%

Jiangmin
Trojan/Menti.pcq, Trojan/JmGeneric.aee, AdWare/WhiteSmoke.m
29.03%

ViRobot
Trojan.Win32.A.Agent.530256[UPX]
25.81%

F-Prot
W32/InstallCore.I.gen, W32/WhiteSmoke.C.gen
25.81%

McAfee Web Gateway
Artemis!67DEFB077C02, Generic.tra!b, Artemis!09A9E5B98BB5, Artemis!1EE1EFEC5A98, Artemis!AC38E5534922, Heuristic.BehavesLike.Win32.ModifiedUPX.C
25.81%

Malwarebytes
Adware.Agent, PUP.Optional.Conduit.A
25.81%

Trend Micro House Call
TROJ_GEN.F47V1024, TROJ_GEN.R4FH1HN, TROJ_GE.E6F1AD8E, TROJ_GEN.F47V1112, TROJ_GEN.F47V0602, TROJ_SPNR.03D511, TROJ_GEN.R0CBB01LS13
25.81%

McAfee
Artemis!67DEFB077C02, Generic.tra!b, Artemis!09A9E5B98BB5, Artemis!1EE1EFEC5A98, Artemis!AC38E5534922, Artemis!C3C8B942131E, Artemis!E9289DEA86F4
22.58%

Sophos
Install Core Installer
22.58%

The domain get.whitesmoke.com has been seen to resolve to the following 29 IP addresses.

ec2-54-187-58-159.us-west-2.compute.amazonaws.com
August 27, 2016

ec2-52-33-237-183.us-west-2.compute.amazonaws.com
August 27, 2016

ec2-52-42-170-11.us-west-2.compute.amazonaws.com
August 14, 2016

ec2-52-11-142-33.us-west-2.compute.amazonaws.com
August 14, 2016

ec2-52-32-162-125.us-west-2.compute.amazonaws.com
July 31, 2016

ec2-50-112-187-121.us-west-2.compute.amazonaws.com
July 31, 2016

ec2-52-32-241-78.us-west-2.compute.amazonaws.com
June 24, 2016

ec2-50-112-148-29.us-west-2.compute.amazonaws.com
June 24, 2016

ec2-52-33-246-56.us-west-2.compute.amazonaws.com
June 21, 2016

ec2-52-36-137-56.us-west-2.compute.amazonaws.com
June 21, 2016

ec2-54-191-47-121.us-west-2.compute.amazonaws.com
May 27, 2016

ec2-52-35-124-6.us-west-2.compute.amazonaws.com
May 27, 2016

ec2-52-27-25-94.us-west-2.compute.amazonaws.com
May 16, 2016

ec2-52-35-111-151.us-west-2.compute.amazonaws.com
May 16, 2016

ec2-54-149-227-220.us-west-2.compute.amazonaws.com
April 22, 2016

ec2-52-10-140-21.us-west-2.compute.amazonaws.com
April 22, 2016

ec2-54-244-2-132.us-west-2.compute.amazonaws.com
April 13, 2016

ec2-54-187-131-122.us-west-2.compute.amazonaws.com
April 13, 2016

ec2-52-10-131-223.us-west-2.compute.amazonaws.com
April 4, 2016

ec2-52-35-44-24.us-west-2.compute.amazonaws.com
April 4, 2016

ec2-52-35-236-42.us-west-2.compute.amazonaws.com
March 2, 2016

ec2-52-11-131-144.us-west-2.compute.amazonaws.com
March 2, 2016

ec2-52-10-95-52.us-west-2.compute.amazonaws.com
February 28, 2016

ec2-54-187-74-110.us-west-2.compute.amazonaws.com
February 28, 2016

ec2-52-11-63-189.us-west-2.compute.amazonaws.com
February 10, 2016

ec2-54-149-49-23.us-west-2.compute.amazonaws.com
February 10, 2016

ec2-54-186-136-182.us-west-2.compute.amazonaws.com
January 3, 2016

ec2-54-191-109-151.us-west-2.compute.amazonaws.com
January 3, 2016

December 29, 2013

File downloads found at URLs served by get.whitesmoke.com.

7 / 68      (Adware)

1 / 68      (Adware)
http://get.whitesmoke.com/WhiteSmokeTranslator5045_en.exe  (683fc500f59769e1f27314a3ee434cc0)

18 / 68    (Adware)

1 / 68      (Adware)

22 / 68    (PUP)
http://get.whitesmoke.com/.../WhiteSmokeInstaller.exe  (e9289dea86f4e9310e8e1042775556e3)

7 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://get.whitesmoke.com/WhiteSmokeWriterExpert.exe  (230687e485cb0a5f52e4cb4196163233)

2 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

2 / 68      (Adware)

2 / 68      (Adware)

2 / 68      (Adware)

1 / 68      (Adware)
http://get.whitesmoke.com/whitesmoke_install.exe  (12060662a35c6e0bcb47284cd851ad98)

6 / 68      (Adware)

31 / 68    (PUP)

2 / 68      (Adware)

3 / 68      (Adware)
http://get.whitesmoke.com/WhiteSmokeWriterPro.exe  (83360ea3da66866a7c681953b585e53d)

15 / 68    (Adware)

2 / 68      (Adware)

2 / 68      (Adware)

2 / 68      (Adware)
http://get.whitesmoke.com/WhiteSmokeWriterTrial.exe  (ab390ac492056f5d672d578045e6930d)

2 / 68      (Adware)
http://get.whitesmoke.com/index.html  (whitesmokewritertrial.exe)

2 / 68      (Adware)

 
Latest 30 of 46 download URLs

URL:
http://get.whitesmoke.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Apache

Compete.com:
US visitors:  613

Statistics are for the previous month.