173.245.61.159

cf-173-245-61-159.cloudflare.com

IP Address Information

The Internet Service Provider (ISP) that owns the network address of 173.245.61.159 is CloudFlare, Inc. and located in California within the United States. The IP Address resolves to the DNS record of cf-173-245-61-159.cloudflare.com. This IP is part of the CloudFlare content delivery network and distributed domain name server service which provides reverse proxy hosting to a number of domains.
Scanner detections:
Detections  (78% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Win.Reputation, Adware.WebPick.Installer.T, Adware.WebPick.Installer.d, Adware.WebPick.Installer.I, Adware.WebPick.Installer.U, Adware.WebPick.Installer.AA, PUP.SergeyPanov.o, Adware.WebPick.Installer.S, Adware.WebPick.Installer.c, Adware.WebPick.Installer.P, Adware.WebPick.Installer.a, PUP.AlexnaderRogozin.k, Adware.WebPick.Installer.FF, Threat.Win.Reputation.IMP, Adware.WebPick.Installer.EE, PUP.AlexnaderRogozin.CC, PUP.IgorKramoren.k, Adware.WebPick.Installer.p, PUP.AlexnaderRogozin.M, Adware.WebPick.Installer.DD, Adware.WebPick.Installer.b
92.86%

Dr.Web
Adware.Downware.2108, Threat.Undefined, Trojan.WebPick.2620, Trojan.Crossrider.24070, Trojan.WebPick.2654, Trojan.WebPick.2627, BackDoor.Andromeda.421
90.48%

NANO AntiVirus
Riskware.Win32.InfoLeak.cvgqot, Virus.Win32.Sality.bzkem, Trojan.Win32.Siggen6.dcscvl, Trojan.Win32.Crossrider.ddnvxt, Riskware.Win32.MultiPlug.ddtvrh
85.71%

Avira AntiVirus
TR/AntiFW.b.109, TR/AntiFW.b.106, TR/Kazy.324119.27, Adware/InstallRex.EL, Adware/InstallRex.G, ADWARE/InstallRex.Gen, W32/Sality.AT
83.33%

Malwarebytes
PUP.Optional.InstalleRex, PUP.Optional.MultiPlug.A, PUP.Optional.Installrex, PUP.Optional.InstalRex, PUP.Optional.InstallRex
80.95%

avast!
Win32:InstalleRex-BX [PUP], Win32:InstalleRex-CC [PUP], Win32:Sality, Win32:InstalleRex-CE [PUP], Win32:InstalleRex-CH [PUP], Win32:Adware-gen [Adw]
80.95%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic, Threat.4786450, Threat.4758034, Threat.4753027
76.19%

Kaspersky
Trojan.Win32.AntiFW, Virus.Win32.Sality, not-a-virus:AdWare.Win32.MultiPlug
76.19%

ESET NOD32
Win32/InstalleRex.M potentially unwanted application, Win32/Sality.NBA virus, Win32/AdWare.MultiPlug.BF application, Win32/AdWare.MultiPlug.AQ application
73.81%

McAfee
PUP-FHQ!6BAC5FB05D56, PUP-FHQ!068F1CE0D70E, W32/Sality.gen.z, PUP-FMK, PUP-FMH, PUP-FHQ!D6BB6F2CE8EA, PUP-FMU, Program.CryptMplug
73.81%

The following domains resolved to the IP address 173.245.61.159.

File URLs download from 173.245.61.159.

34 / 68    (Adware)
http://applicationgrabb.net/.../Download.exe  (f1144cc34e4b452be6dcb9cd50af4a2f)

1 / 68      (Adware)

34 / 68    (Adware)

0 / 68
http://applicationgrabb.net/.../null  (making history ii the war of the world-skidrow.exe)

18 / 68    (Adware)
http://applicationgrabb.net/.../Install File.exe  (a32884aa85c4864081673102676c3f18)

19 / 68    (PUP)
http://applicationgrabb.net/.../V._1.3_AIO.part01.rar.exe  (d1b5a9f0d9f48f924a4e95678ebe68d5)

19 / 68    (PUP)

19 / 68    (PUP)

18 / 68    (PUP)

18 / 68    (Adware)

17 / 68    (PUP)

22 / 68    (PUP)

18 / 68    (Adware)

20 / 68    (PUP)
http://applicationgrabb.net/.../Die Amigos Torrent.exe  (8f44eaa00d694cd7e57505f5bd254351)

27 / 68    (Adware)

40 / 68    (Adware)

19 / 68    (Adware)

16 / 68    (Adware)

0 / 68
http://applicationgrabb.net/null  (facebook account hacker v2.4.exe)

36 / 68    (Adware)

 
Latest 30 of 1,045 download URLs

The geographical location of this IP address.

Country:
United States (US)

Region:
California

City:
San Francisco

Coordinates:
37.7757, -122.395

The ARIN network assigned organization for IP address 173.245.61.159.

Org name:
CloudFlare, Inc.

Org identifier:
CLOUD14

Org country:
United States (US)

Org region:
California

Org city:
San Francisco

Org address:
665 Third Street #207

Org website:
http://www.cloudflare.com/

ARIN WHOIS:

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# http://www.arin.net/public/whoisinaccuracy/index.xhtml
#


#
# The following results may also be obtained via:
NetRange: 173.245.48.0 - 173.245.63.255
CIDR: 173.245.48.0/20
NetName: CLOUDFLARENET
NetHandle: NET-173-245-48-0-1
Parent: NET173 (NET-173-0-0-0-0)
NetType: Direct Assignment
OriginAS: AS13335
Organization: CloudFlare, Inc. (CLOUD14)
RegDate: 2010-12-28
Updated: 2012-03-02
Comment: http://www.cloudflare.com/
Ref: http://whois.arin.net/rest/net/NET-173-245-48-0-1

OrgName: CloudFlare, Inc.
OrgId: CLOUD14
Address: 665 Third Street #207
City: San Francisco
StateProv: CA
PostalCode: 94107
Country: US
RegDate: 2010-07-09
Updated: 2013-01-04
Comment: http://www.cloudflare.com/
Ref: http://whois.arin.net/rest/org/CLOUD14

OrgTechHandle: ADMIN2521-ARIN
OrgTechName: Admin
OrgTechPhone: +1-650-319-8930
OrgTechEmail: admin@cloudflare.com
OrgTechRef: http://whois.arin.net/rest/poc/ADMIN2521-ARIN

OrgAbuseHandle: ABUSE2916-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-650-319-8930
OrgAbuseEmail: abuse@cloudflare.com
OrgAbuseRef: http://whois.arin.net/rest/poc/ABUSE2916-ARIN

OrgNOCHandle: NOC11962-ARIN
OrgNOCName: NOC
OrgNOCPhone: +1-650-319-8930
OrgNOCEmail: noc@cloudflare.com
OrgNOCRef: http://whois.arin.net/rest/poc/NOC11962-ARIN

RNOCHandle: NOC11962-ARIN
RNOCName: NOC
RNOCPhone: +1-650-319-8930
RNOCEmail: noc@cloudflare.com
RNOCRef: http://whois.arin.net/rest/poc/NOC11962-ARIN

RAbuseHandle: ABUSE2916-ARIN
RAbuseName: Abuse
RAbusePhone: +1-650-319-8930
RAbuseEmail: abuse@cloudflare.com
RAbuseRef: http://whois.arin.net/rest/poc/ABUSE2916-ARIN

RTechHandle: ADMIN2521-ARIN
RTechName: Admin
RTechPhone: +1-650-319-8930
RTechEmail: admin@cloudflare.com
RTechRef: http://whois.arin.net/rest/poc/ADMIN2521-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# http://www.arin.net/public/whoisinaccuracy/index.xhtml
#


Remove Malware from 173.245.61.159 - Powered by Reason Core Security