www.lpcloudsvr401.com

Domain Registries Foundation

Domain Information

The domain www.lpcloudsvr401.com registered by Domain Registries Foundation was initially registered in November of 2015 through SOLUCIONES CORPORATIVAS IP,SLU. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
GODADDY.COM, LLC

Server location:
Oregon, United States (US)

Create date:
Wednesday, November 11, 2015

Expires date:
Friday, November 11, 2016

Updated date:
Wednesday, November 11, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (82% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.tuguusl.F, PUP.Bundler.Tuguu, PUP.NewMedia.Installer.Installer (M), PUP.Softpulse.DIGITALPLUGINU.Installer (M), PUP.Tuguu.tuguusl.Bundler (M)
80.00%

McAfee
Artemis!D4B5325B4C72, CryptDomaIQ, Program.CryptDomaIQ, Artemis!C59C262EF094, Artemis!05F6E2A07415
50.00%

K7 Gateway Antivirus
Unwanted-Program , Riskware , Adware
50.00%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious.H, BehavesLike.Win32.CryptDoma.fh, BehavesLike.Win32.CryptDoma.fm, BehavesLike.Win32.BadFile.nh
50.00%

IKARUS anti.virus
AdWare.DomaIQ, PUA.DomaIQ, Trojan-Downloader.Agent, PUA.InstallCore
50.00%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A, Threat.Undefined, TrojanDownloader:Win32/Unlacehi.A
40.00%

Malwarebytes
PUP.Optional.BundleInstaller.A, PUP.Optional.Domalq, PUP.Optional.InstallCore
40.00%

Sophos
DomainIQ pay-per install, PUA 'DomainIQ pay-per install', Install Core Click run software (PUA)
40.00%

Dr.Web
Trojan.DownLoader9.24409, Trojan.MulDrop5.9989, Trojan.DownLoader9.21779, Trojan.Installcore.633
40.00%

VIPRE Antivirus
DomaIQ, Trojan.Win32.Generic, Threat.4783262, InstallCore
40.00%

Avira AntiVirus
APPL/DomaIQ.Gen, Adware/MSIL.DomaIQ.amvu.1, PUA/DomaIQ.Gen, TR/Dldr.Agent.33754
40.00%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/MSIL.DomaIQ, GrayWare[Adware]/Win32.installcore.aaj
40.00%

AVG
Skodna.Bundle_r.Z, Adware DomaIQ.V, Adware Skodna.Bundle_r.Y, Generic
40.00%

K7 AntiVirus
Unwanted-Program , Riskware , Adware
40.00%

Agnitum Outpost
PUA.DomaIQ
30.00%

The domain www.lpcloudsvr401.com has been seen to resolve to the following 8 IP addresses.

February 25, 2016

ec2-54-213-71-128.us-west-2.compute.amazonaws.com
November 10, 2014

ec2-54-186-187-58.us-west-2.compute.amazonaws.com
November 10, 2014

ec2-54-218-30-251.us-west-2.compute.amazonaws.com
April 4, 2014

ec2-54-201-9-67.us-west-2.compute.amazonaws.com
April 4, 2014

ec2-54-201-189-9.us-west-2.compute.amazonaws.com
April 4, 2014

ec2-54-200-4-93.us-west-2.compute.amazonaws.com
April 4, 2014

ec2-54-201-153-98.us-west-2.compute.amazonaws.com
April 4, 2014

File downloads found at URLs served by www.lpcloudsvr401.com.

0 / 68
http://www.lpcloudsvr401.com/.../Setup.exe  (63c5952ef61c4c3c18cb13068b5fce08)

1 / 68      (Adware)
http://www.lpcloudsvr401.com/.../Setup.exe  (8553c0c6e3342d6861e9d273998f56aa)

1 / 68      (Adware)
http://www.lpcloudsvr401.com/.../Setup.exe  (48d107a60b622431f49dccf545d12795)

1 / 68      (Adware)
http://www.lpcloudsvr401.com/.../Setup.exe  (09e3a3e1143280bfcfca86b91cedfcb7)

2 / 68      (false positives)

18 / 68    (Adware)
http://www.lpcloudsvr401.com/.../Setup.exe  (05f6e2a07415d0278d75fea97f789095)

9 / 68      (PUP)
http://www.lpcloudsvr401.com/.../Setup.exe  (c59c262ef09455a8817b9df404a03cb7)

1 / 68      (PUP)
http://www.lpcloudsvr401.com/.../Setup.exe  (911e5dbcc497986f53c12d48b13ed8b8)

40 / 68    (Adware)
http://www.lpcloudsvr401.com/.../Setup.exe  (efb8d5bb51f47c137e9715c77df904d8)

37 / 68    (Adware)
http://www.lpcloudsvr401.com/.../Setup.exe  (27a3d8c570a2fc0669d232cb31343031)

21 / 68    (Adware)
http://www.lpcloudsvr401.com/.../Setup.exe  (05265ce8ba3336266744c1700c12dcf9)

The following 4 files have been seen to comunicate with www.lpcloudsvr401.com in live environments.

URL:
http://www.lpcloudsvr401.com/

Title:
“lpcloudsvr401.com”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Apache

Facebook:
Shares:  2

Statistics are for the previous month.