The domain mp3clan.com registered by Registration Privacy, No-IP.com was initially registered in April of 2012 through VITALWERKS INTERNET SOLUTIONS LLC DBA NO-IP. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Irkutsk, Irkutsk within Russia which resides on the RIPE Network Coordination Centre network.
VITALWERKS INTERNET SOLUTIONS LLC DBA NO-IP
Irkutsk, Russia (RU)
Monday, April 23, 2012
Tuesday, April 23, 2019
Thursday, April 10, 2014
AS29182 ISPSYSTEM-AS ISPsystem, cjsc,LU
Detections (100% detected)
Adware.WebPick.Installer.g, Adware.WebPick.Installer.Z, Adware.WebPick.Installer.FF, PUP.SITEONSPOT.m, PUP.SITEONSPOT.y, Adware.WebPick.Installer.m, Adware.WebPick.Installer.EE, PUP.WebPick.Installer, Adware.WebPick.Installer (M), PUP.Somoto.SITEONSPOT.Bundler (M)
Win32:InstalleRex-BI [PUP], Win32:InstalleRex-BO [PUP], Win32:Somoto-P [PUP], Win32:InstalleRex-CD [PUP]
PUP.Optional.Installrex, PUP.Optional.InstalleRex, PUP.Optional.Somoto.A
Installerex/WebPick, Threat.4753027, Trojan.Win32.Generic, BetterInstaller, Threat.4150696
K7 Gateway Antivirus
Unwanted-Program , Trojan , Adware
InstallRex, Somoto BetterInstaller, PUA 'InstallRex'
Trojan.WebPick.29, Trojan.WebPick.2452, Trojan.Packed.26824
TR/Rogue.11241865, ADWARE/InstallRex.Gen, Adware/Kazy.207317.6, APPL/Somoto.hzis, TR/Rogue.11227301, TR/AntiFW.b.50
Antiy Labs AVL
RiskWare[Downloader:not-a-virus,HEUR]/Win32.AdLoad, Trojan/Win32.AntiFW.b, Adware[:not-a-virus]/Win32.Agent.allm
McAfee Web Gateway
PUP-FHQ!D85F62B783A8, PUP-FHQ!99D13F43428B, Artemis, Somoto-BetterInstaller, BehavesLike.Win32.SomotoBetterInstaller.dc
PUP-FHQ!D85F62B783A8, PUP-FHQ!99D13F43428B, Artemis!09F76B296855, Somoto-BetterInstaller, Program.PUP-FHQ, Artemis!602B2E2D7679
Unwanted-Program , Adware
The domain mp3clan.com has been seen to resolve to the following 6 IP addresses.
November 7, 2015
File downloads found at URLs served by mp3clan.com.
“mp3 Supply - Free Music Download”
“Free music downloads. mp3 Supply is an mp3 search engine allowing its users to listen to music online also enabling free mp3 downloads for all your favorite songs.”
SSL certificate subject:
CN=sni49761.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated
SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB
Statistics above are for the previous month of February 2017.