The domain get.whitesmoke.com registered by WhiteSmoke, Inc was initially registered in June of 2001 through TIERRANET INC. D/B/A DOMAINDISCOVER. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrant:
WhiteSmoke, Inc
Registrar:
TIERRANET INC. D/B/A DOMAINDISCOVER
Server location:
Oregon, United States (US)
Create date:
Tuesday, June 19, 2001
Expires date:
Tuesday, June 19, 2018
Updated date:
Wednesday, June 19, 2013
ASN:
AS16509 AMAZON-02 - Amazon.com, Inc., US
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.WhiteSmoke.AA, PUP.Installer.WhiteSmoke.Y, PUP.Installer.WhiteSmoke.T, (M), PUP.WhiteSmoke.X, PUP.WhiteSmoke.V, PUP.WhiteSmoke.K, PUP.WhiteSmoke.Installer (M), PUP.WhiteSmoke.InstallCoreC.Installer (M), PUP.WhiteSmoke.InstallC.Installer (M), PUP.WhiteSmoke.InstallB.Installer (M), PUP.Amonetize.Bundler (M), PUP.WhiteSmoke (M)
87.10%
ESET NOD32
Win32/WhiteSmoke (variant), Win32/InstallCore (variant), Win32/InstallCore.LG (variant), Win32/OpenCandy, Win32/TrojanDownloader.Whizelown (variant)
58.06%
avast!
Win32:WhiteSmoke-A [PUP], Win32:InstallCore-BA [PUP], Win32:Dropper-gen [Drp], Win32:PUP-gen [PUP]
41.94%
Dr.Web
Adware.InstallCore.3, Trojan.MulDrop5.10078, Trojan.DownLoader3.37078, Adware.Conduit.6, Trojan.MulDrop2.8152, Adware.WhiteSmoke.3
41.94%
Comodo Security
Heur.Suspicious, Application.Win32.InstallCore.BWAN, ApplicUnwnt.Win32.Adware.WhiteSmoke.dy01
38.71%
VIPRE Antivirus
Trojan.Win32.Generic, WhiteSmoke (not malicious), Conduit
32.26%
Avira AntiVirus
Adware/WhiteSmoke.B.30, ADWARE/InstallCore.Gen, ADWARE/Adware.Gen
29.03%
ViRobot
Trojan.Win32.A.Agent.530256[UPX]
25.81%
F-Prot
W32/InstallCore.I.gen, W32/WhiteSmoke.C.gen
25.81%
Malwarebytes
Adware.Agent, PUP.Optional.Conduit.A
25.81%
Trend Micro House Call
TROJ_GEN.F47V1024, TROJ_GEN.R4FH1HN, TROJ_GE.E6F1AD8E, TROJ_GEN.F47V1112, TROJ_GEN.F47V0602, TROJ_SPNR.03D511, TROJ_GEN.R0CBB01LS13
25.81%
McAfee
Artemis!67DEFB077C02, Generic.tra!b, Artemis!09A9E5B98BB5, Artemis!1EE1EFEC5A98, Artemis!AC38E5534922, Artemis!C3C8B942131E, Artemis!E9289DEA86F4
22.58%
Sophos
Install Core Installer
22.58%
Fortinet FortiGate
W32/Tra.B!tr, Riskware/InstallCore, Adware/WhiteSmoke
19.35%
Vba32 AntiVirus
Downware.InstallCore, AdWare.WhiteSmoke
12.90%
The domain get.whitesmoke.com has been seen to resolve to the following 29 IP addresses.
ec2-54-187-58-159.us-west-2.compute.amazonaws.com
August 27, 2016
ec2-52-33-237-183.us-west-2.compute.amazonaws.com
August 27, 2016
ec2-52-42-170-11.us-west-2.compute.amazonaws.com
August 14, 2016
ec2-52-11-142-33.us-west-2.compute.amazonaws.com
August 14, 2016
ec2-52-32-162-125.us-west-2.compute.amazonaws.com
July 31, 2016
ec2-50-112-187-121.us-west-2.compute.amazonaws.com
July 31, 2016
ec2-52-32-241-78.us-west-2.compute.amazonaws.com
June 24, 2016
ec2-50-112-148-29.us-west-2.compute.amazonaws.com
June 24, 2016
ec2-52-33-246-56.us-west-2.compute.amazonaws.com
June 21, 2016
ec2-52-36-137-56.us-west-2.compute.amazonaws.com
June 21, 2016
ec2-54-191-47-121.us-west-2.compute.amazonaws.com
May 27, 2016
ec2-52-35-124-6.us-west-2.compute.amazonaws.com
May 27, 2016
ec2-52-27-25-94.us-west-2.compute.amazonaws.com
May 16, 2016
ec2-52-35-111-151.us-west-2.compute.amazonaws.com
May 16, 2016
ec2-54-149-227-220.us-west-2.compute.amazonaws.com
April 22, 2016
ec2-52-10-140-21.us-west-2.compute.amazonaws.com
April 22, 2016
ec2-54-244-2-132.us-west-2.compute.amazonaws.com
April 13, 2016
ec2-54-187-131-122.us-west-2.compute.amazonaws.com
April 13, 2016
ec2-52-10-131-223.us-west-2.compute.amazonaws.com
April 4, 2016
ec2-52-35-44-24.us-west-2.compute.amazonaws.com
April 4, 2016
ec2-52-35-236-42.us-west-2.compute.amazonaws.com
March 2, 2016
ec2-52-11-131-144.us-west-2.compute.amazonaws.com
March 2, 2016
ec2-52-10-95-52.us-west-2.compute.amazonaws.com
February 28, 2016
ec2-54-187-74-110.us-west-2.compute.amazonaws.com
February 28, 2016
ec2-52-11-63-189.us-west-2.compute.amazonaws.com
February 10, 2016
ec2-54-149-49-23.us-west-2.compute.amazonaws.com
February 10, 2016
ec2-54-186-136-182.us-west-2.compute.amazonaws.com
January 3, 2016
ec2-54-191-109-151.us-west-2.compute.amazonaws.com
January 3, 2016
File downloads found at URLs served by get.whitesmoke.com.
Latest 30 of 46 download URLs
URL:
http://get.whitesmoke.com/
Network:
Amazon Web Services (AWS), running an EC2 instance
Statistics are for the previous month.