squid.cluster1.amber1graph.com

Whois Privacy Corp.

Domain Information

The domain squid.cluster1.amber1graph.com registered by Whois Privacy Corp. was initially registered in January of 2015 through TLD REGISTRAR SOLUTIONS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
TLD REGISTRAR SOLUTIONS LTD

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Saturday, January 10, 2015

Expires date:
Sunday, January 10, 2016

Updated date:
Friday, January 30, 2015

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

avast!
Win32:Malware-gen, Win32:Amonetize-HQ [PUP]
100.00%

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
100.00%

AVG
Generic
100.00%

Reason Heuristics
PUP.Installer.AMGRUP., PUP.Installer.ShetefSolutionsConsulting1998.v, PUP.Installer.AMGRUP.o
100.00%

MicroWorld eScan
Trojan.GenericKD.2067331, Gen:Variant.Application.Bundler.Amonetize.21
100.00%

K7 AntiVirus
Trojan
100.00%

NANO AntiVirus
Trojan.Win32.Adfltnet.dlsvsx, Trojan.Win32.Adfltnet.dlwosi
100.00%

Trend Micro House Call
Suspicious_GEN.F47V0107, Suspicious_GEN.F47V0112, TROJ_GEN.R02SH07AB15
100.00%

Bitdefender
Trojan.GenericKD.2067331, Gen:Variant.Application.Bundler.Amonetize.21
100.00%

Lavasoft Ad-Aware
Trojan.GenericKD.2067331, Gen:Variant.Application.Bundler.Amonetize.21
100.00%

F-Secure
Trojan.GenericKD.2067331, Gen:Variant.Application.Bundler
100.00%

Dr.Web
Trojan.Adfltnet.70, Trojan.Adfltnet.71
100.00%

Sophos
Generic PUA JG, Generic PUA JA, Generic PUA LF
100.00%

Avira AntiVirus
TR/Crypt.ZPACK.Gen2, ADWARE/Adware.Gen4
100.00%

AhnLab V3 Security
PUP/Win32.Amonetiz
100.00%

The domain squid.cluster1.amber1graph.com has been seen to resolve to the following IP address.

unallocated.barefruit.co.uk
May 4, 2015

File downloads found at URLs served by squid.cluster1.amber1graph.com.

The following 230 files have been seen to comunicate with squid.cluster1.amber1graph.com in live environments.

 
Latest 20 of 230 files

URL:
http://squid.cluster1.amber1graph.com/

Web server:
nginx/1.0.15