squid.cluster4.ambergraph.com

Whois Privacy Corp.

Domain Information

The domain squid.cluster4.ambergraph.com registered by Whois Privacy Corp. was initially registered in December of 2014 through TLD REGISTRAR SOLUTIONS LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Singapore, Singapore within Singapore which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
TLD REGISTRAR SOLUTIONS LTD

Server location:
Singapore, Singapore (SG)

Create date:
Wednesday, December 10, 2014

Expires date:
Thursday, December 10, 2015

Updated date:
Wednesday, December 10, 2014

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

avast!
Win32:Malware-gen
100.00%

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
100.00%

AVG
Generic
100.00%

Reason Heuristics
PUP.Installer.AMGRUP.
100.00%

Bkav FE
HW32.Packed
100.00%

MicroWorld eScan
Trojan.GenericKD.2067331
100.00%

nProtect
Trojan.GenericKD.2067331
100.00%

K7 AntiVirus
Trojan
100.00%

NANO AntiVirus
Trojan.Win32.Adfltnet.dlsvsx
100.00%

Trend Micro House Call
Suspicious_GEN.F47V0107
100.00%

Bitdefender
Trojan.GenericKD.2067331
100.00%

Lavasoft Ad-Aware
Trojan.GenericKD.2067331
100.00%

Emsisoft Anti-Malware
Trojan.GenericKD.2067331
100.00%

F-Secure
Trojan.GenericKD.2067331
100.00%

Dr.Web
Trojan.Adfltnet.70
100.00%

The domain squid.cluster4.ambergraph.com has been seen to resolve to the following 2 IP addresses.

May 4, 2015

May 4, 2015

File downloads found at URLs served by squid.cluster4.ambergraph.com.

URL:
http://squid.cluster4.ambergraph.com/

Web server:
cloudflare-nginx (PHP/5.3.3)