clipskeeper.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain clipskeeper.com is registered by proxy through ENOM, INC. and was originally registered in November of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Friday, November 23, 2012

Expires date:
Wednesday, November 23, 2016

Updated date:
Saturday, December 19, 2015

ASN:
AS39572 ADVANCEDHOSTERS-AS ADVANCEDHOSTERS LIMITED

Scanner detections:
Detections  (80% detected)

Scan engine
Details
Detections

avast!
Win32:Adware-BJY [PUP], Win32:Amonetize-P [PUP], Win32:Amonetize-AM [PUP], Win32:Amonetize-BJ [PUP], Win32:Dropper-gen [Drp], NSIS:InstMonetizer-AK [PUP]
80.00%

Malwarebytes
PUP.Optional.Amonetize.A, PUP.Optional.Handy.A, PUP.Optional.Remarkit
70.00%

Dr.Web
Adware.Downware.1575, Adware.Downware.2467, Adware.Downware.3925, Adware.Downware.1584, Detection.Undefined
60.00%

ESET NOD32
Win32/Amonetize.AG (variant), Win32/Amonetize.AI (variant), Win32/Amonetize.AJ (variant), Win32/Amonetize.AS (variant), Win32/ActiveMonetizer
60.00%

Qihoo 360 Security
Win32/Virus.Adware.47b, Win32/Trojan.Adware.37e, Win32/Virus.Adware.932, Win32/Trojan.Dropper.c9f
50.00%

Reason Heuristics
PUP.Installer.ShetefSolutionsConsulting1998.?, PUP.Wilmaonline.R, PUP.Installer.Amonetizeltd.a, Threat.Win.Reputation.IMP
40.00%

McAfee
Artemis!8D3386F3ACE9, Artemis!3D7A2AAABBBC, Artemis!52DE26D456C5, PUP-FBM!2C78E5FBC36C
40.00%

Sophos
Amonetize
40.00%

Avira AntiVirus
ADWARE/Adware.Gen2
40.00%

AhnLab V3 Security
PUP/Win32.Amonetiz
40.00%

Trend Micro House Call
TROJ_GEN.F47V0303, TROJ_GEN.F47V0310, TROJ_GEN.F47V0412
30.00%

AVG
MalSign.Wilmo, Generic_r
30.00%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize, not-a-virus:HEUR:AdWare.Win32.Yotoon
30.00%

Rising Antivirus
PE:Malware.Adware!6.17D8, NS:AdWare.Script.VBS.StartPage.g!1579249
30.00%

NANO AntiVirus
Riskware.Win32.Downware.cyusqp, Riskware.Nsis.Yontoo.cwhuxq
30.00%

The domain clipskeeper.com has been seen to resolve to the following IP address.

February 9, 2014

File downloads found at URLs served by clipskeeper.com.

3 / 68      (PUP)
http://clipskeeper.com/.../14176  (gotclip_setup.exe)

11 / 68    (Adware)
http://clipskeeper.com/.../36990  (ares__2309_il1424.exe)

2 / 68      (inconclusive)
http://clipskeeper.com/.../36990  (gotclip_setup.exe)

3 / 68      (PUP)
http://clipskeeper.com/.../36990  (gotclip_setup.exe)

7 / 68      (PUP)
http://clipskeeper.com/.../14177  (gotclip_setup.exe)

6 / 68      (PUP)
http://clipskeeper.com/.../14176  (gotclip_setup.exe)

16 / 68    (PUP)
http://clipskeeper.com/.../36990  (microsoft.office.professional__2309_il15470.exe)

11 / 68    (Adware)
http://clipskeeper.com/.../36990  (minecraft premium account gene downloader__3687_i400818195_il6490054.exe)

16 / 68    (Adware)
http://clipskeeper.com/.../36990  (setup__6666_i558241476_il1884594.exe)

1 / 68
http://clipskeeper.com/.../36990  (gotclip_setup.exe)

March 27, 2014

URL:
http://clipskeeper.com/

Google Analytics:
UA-23390261

Title:
“GotCLIP Downloader -”

Web server:
Apache/2.2.23 (Unix) PHP/5.2.17 (PHP/5.2.17)