dexclock.de

Domain Information

Server location:
Berlin, Germany (DE)

ASN:
AS6724 STRATO STRATO AG,DE

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.OpenCandy
100.00%

ESET NOD32
Win32/OpenCandy, Win32/OpenCandy (variant)
100.00%

Trend Micro House Call
TROJ_GEN.F47V1206, Suspicious_GEN.F47V0722, Suspicious_GEN.F47V1111
75.00%

McAfee
Artemis!A2AF6FFBAEB6, Artemis!3B7FC715BA51
50.00%

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
50.00%

Fortinet FortiGate
Riskware/OpenCandy
50.00%

Bkav FE
W32.Cloda9b.Trojan
25.00%

K7 AntiVirus
Trojan
25.00%

IKARUS anti.virus
PUA.JoyDownloader
25.00%

Agnitum Outpost
Riskware.Agent
25.00%

Dr.Web
Adware.OpenCandy.55
25.00%

The domain dexclock.de has been seen to resolve to the following 2 IP addresses.

w04.rzone.de
June 5, 2016

srv3.sysproserver.de
December 28, 2013

File downloads found at URLs served by dexclock.de.

7 / 68      (PUP)
http://dexclock.de/.../dexclock_13_r39.exe  (3b7fc715ba51b701e7a7497676bc5938)

4 / 68      (PUP)
http://dexclock.de/.../dexclock_13_r39.exe  (23511487f8388dd12876d403507abdba)

7 / 68      (PUP)
http://dexclock.de/.../dexclock_13_r39.exe  (a2af6ffbaeb660365224d3756cfd4fd3)

4 / 68      (PUP)
http://dexclock.de/.../dexclock_12_r32.exe  (017753d57f91890c81d039b57ac9b4db)

The following 5 files have been seen to comunicate with dexclock.de in live environments.

June 5, 2016