www.lpcloudsvr303.com

Pheenix, Inc.

Domain Information

The domain www.lpcloudsvr303.com registered by Pheenix, Inc. was initially registered in March of 2015 through SOLUCIONES CORPORATIVAS IP,SLU. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
INTERSOLVED-WA.COM INC.

Server location:
Oregon, United States (US)

Create date:
Thursday, March 5, 2015

Expires date:
Sunday, March 5, 2017

Updated date:
Saturday, March 12, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (97% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.TuguuSL.F, PUP.Installer.TuguuSL.I, PUP.Systweak.TUNEUPPR.Installer.Meta (L), PUP.Tuguu.TuguuSL.Bundler (M), PUP.Tuguu.Bundler (M), PUP.NewMedia.Installer.Installer (M), PUP.Tuguu.tuguusl.Bundler (M), PUP.Vittalia.InstallAssistant.Installer (M), PUP.Softpulse.DigitalP.Bundler (M), PUP.Softpulse.VolvanPr.Installer (M), PUP.Tuguu.Installer (M), PUP.Tuguu (M)
97.37%

Dr.Web
Trojan.MulDrop5.9989, Trojan.DownLoader9.21779, Adware.Downware.6176
7.89%

AVG
Adware DomaIQ.V, Skodna.Bundle_r.Y, Trojan horse Downloader.Generic13.CLLF.dropper
7.89%

avast!
DomaIQ-CC [PUP], Win32:PUP-gen [PUP], Win32:DomaIQ-BP [PUP]
7.89%

VIPRE Antivirus
Threat.4150696, DomaIQ
7.89%

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ, not-a-virus:AdWare.Win32.Lollipop
7.89%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A, Threat.Undefined
5.26%

ESET NOD32
Win32/DomaIQ.BA potentially unwanted application, Win32/DomaIQ.BB potentially unwanted application
5.26%

MicroWorld eScan
Application.Generic.603284, Gen:Variant.Application.Bundler.DomaIQ.3
5.26%

McAfee
CryptDomaIQ, Adware-DomaIQ!87EAB94F6E66
5.26%

Malwarebytes
PUP.Optional.Domalq, PUP.Optional.BundleInstaller.A
5.26%

K7 AntiVirus
Unwanted-Program
5.26%

NANO AntiVirus
Trojan.Win32.DomaIQ.cwydit, Trojan.Win32.DomaIQ.ctadmg
5.26%

F-Prot
W32/A-ab59c31e, W32/DomaIQ.D.gen
5.26%

Bitdefender
Application.Generic.603284, Gen:Variant.Application.Bundler.DomaIQ.3
5.26%

The domain www.lpcloudsvr303.com has been seen to resolve to the following 5 IP addresses.

November 7, 2015

ec2-54-244-30-115.us-west-2.compute.amazonaws.com
August 17, 2014

ec2-54-186-83-158.us-west-2.compute.amazonaws.com
August 17, 2014

ec2-54-201-220-135.us-west-2.compute.amazonaws.com
June 22, 2014

ec2-54-201-153-98.us-west-2.compute.amazonaws.com
June 22, 2014

File downloads found at URLs served by www.lpcloudsvr303.com.

1 / 68      (Adware)
http://www.lpcloudsvr303.com/.../Player_Setup.exe  (defd2d3f76978885986ffb0f37f97d36)

1 / 68      (Adware)
http://www.lpcloudsvr303.com/.../Setup.exe  (414df319c4b0b12c6ec37d3b67864098)

1 / 68      (Adware)
http://www.lpcloudsvr303.com/.../Player.exe  (ee2f30cdfb32a7e1f798d46bc6811bf2)

9 / 68      (Adware)
http://www.lpcloudsvr303.com/.../Setup_V2.exe  (4c947178d48a08a86c13194ea988ecd3)

The following 2 files have been seen to comunicate with www.lpcloudsvr303.com in live environments.

Facebook:
Shares:  4

Statistics are for the previous month.