www.megacleancapital.com

Domain Information

Server location:
Washington, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

avast!
Win32:Malware-gen
100.00%

ESET NOD32
Win32/InstallCore.AFV potentially unwanted (variant)
50.00%

AhnLab V3 Security
PUP/Win32.Downloader
50.00%

Qihoo 360 Security
HEUR/QVM20.1.Malware.Gen
50.00%

ESET NOD32
Win32/InstallCore.AFV potentially unwanted application
50.00%

The domain www.megacleancapital.com has been seen to resolve to the following 16 IP addresses.

server-52-84-125-73.iad16.r.cloudfront.net
May 24, 2016

server-52-84-125-56.iad16.r.cloudfront.net
May 24, 2016

server-52-84-125-19.iad16.r.cloudfront.net
May 24, 2016

server-52-84-125-242.iad16.r.cloudfront.net
May 24, 2016

server-52-84-125-176.iad16.r.cloudfront.net
May 24, 2016

server-52-84-125-146.iad16.r.cloudfront.net
May 24, 2016

server-52-84-125-135.iad16.r.cloudfront.net
May 24, 2016

server-52-84-125-116.iad16.r.cloudfront.net
May 24, 2016

server-52-85-131-167.iad53.r.cloudfront.net
April 12, 2016

server-52-85-131-155.iad53.r.cloudfront.net
April 12, 2016

server-52-85-131-114.iad53.r.cloudfront.net
April 12, 2016

server-52-85-131-51.iad53.r.cloudfront.net
April 12, 2016

server-52-85-131-30.iad53.r.cloudfront.net
April 12, 2016

server-52-85-131-235.iad53.r.cloudfront.net
April 12, 2016

server-52-85-131-206.iad53.r.cloudfront.net
April 12, 2016

server-52-85-131-196.iad53.r.cloudfront.net
April 12, 2016

File downloads found at URLs served by www.megacleancapital.com.

2 / 68      (PUP)
http://www.megacleancapital.com/.../installer.exe  (47138ab30e449c2cf411de296e384e2c)

4 / 68      (PUP)
http://www.megacleancapital.com/.../installer.exe  (888c0d76f47041abe7c5e013c5112f8c)

The following 15 files have been seen to comunicate with www.megacleancapital.com in live environments.

 
Latest 20 of 36 files