Server location:
Washington, United States (US)
ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US
Scanner detections:
Malware distribution (96% detected)
Scan engine
Details
Detections
ESET NOD32
Win32/InstallCore.AEO.gen potentially unwanted application, Win32/InstallCore.AFN.gen potentially unwanted application, Win32/InstallCore.ACY.gen potentially unwanted application, Win32/InstallCore.AFW potentially unwanted application, Win32/InstallCore.AFY potentially unwanted application, Win32/InstallCore.AFO.gen potentially unwanted application, Win32/VB.QQC trojan, Win32/Sality.NAR virus, Win32/InstallCore.ACP.gen potentially unwanted application, Win32/Sality.NBA virus, Win32/Agent.NAG virus
81.63%
avast!
Win32:Malware-gen, Win32:SaliCode, Win32:Sality, Win32:FileInfector-A [Heur], Win32:Kukacka, Win32:VB-OJQ [Wrm], Win32:Patched-JI
63.27%
F-Prot
W32/Sality.gen2, W32/VB.AD.gen, W32/Sality.AK, W32/Sality.E.gen, W32/Virut.AI!Generic, W32/Slugin.B
57.14%
McAfee
Artemis!05BA2C8937AA, Artemis!0FD3D2207301, Artemis!0756591F5975, Artemis!6102F6BBEB39, Artemis!01F7F52C5EE3, Artemis!57C8EDE2C92A
55.10%
Kaspersky
Virus.Win32.Sality, Trojan-Dropper.Win32.VB, Trojan.Win32.Agent, Virus.Win32.Slugin
55.10%
Microsoft Security Essentials
Worm:Win32/NeksMiner.A, Threat.Undefined
53.06%
Dr.Web
Trojan.InstallCore.1683, Trojan.InstallCore.1681, Trojan.InstallCore.978, Adware.InstallCore.653, Win32.Sector.30, Win32.Sector.22
48.98%
Norman
Win32.Sality.3, Trojan.Generic.8613015, Win32.Sality.OG, Win32.SlugIn.A
42.86%
Reason Heuristics
Adware.Bundler (M), Threat.Win.Reputation.IMP
40.82%
F-Secure
Application:W32/Generic.70053c248f!Online, Win32.Sality.3, Trojan.Generic.8613015, Win32.Sality.OG, Trojan.Heur.VP2.HmNfaiFex0fi
38.78%
Emsisoft Anti-Malware
Win32.Sality, Trojan.Generic.8613015, Win32.Sality.OG, Gen:Trojan.Heur.VP2.HmNfaiFex0fi, Win32.SlugIn
38.78%
AVG
Win32/Sality, Win32/Slugin.A
36.73%
AhnLab V3 Security
PUP/Win32.Downloader
16.33%
VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic, Threat.4721115, Threat.416209
16.33%
Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F], PE:Adware.InstallCore!1.A30C [F], PE:Malware.Generic(Thunder)!1.A1C4 [F]
10.20%
The domain www.sharecapitalclear.com has been seen to resolve to the following 86 IP addresses.
server-52-84-125-79.iad16.r.cloudfront.net
August 22, 2016
server-52-84-125-75.iad16.r.cloudfront.net
August 22, 2016
server-52-84-125-31.iad16.r.cloudfront.net
August 22, 2016
server-52-84-125-4.iad16.r.cloudfront.net
August 22, 2016
server-52-84-125-217.iad16.r.cloudfront.net
August 22, 2016
server-52-84-125-114.iad16.r.cloudfront.net
August 22, 2016
server-52-84-125-102.iad16.r.cloudfront.net
August 22, 2016
server-52-84-125-90.iad16.r.cloudfront.net
August 22, 2016
server-52-84-125-43.iad16.r.cloudfront.net
August 18, 2016
server-52-84-125-11.iad16.r.cloudfront.net
August 18, 2016
server-52-84-125-239.iad16.r.cloudfront.net
August 18, 2016
server-52-84-125-160.iad16.r.cloudfront.net
August 18, 2016
server-52-84-125-95.iad16.r.cloudfront.net
August 18, 2016
server-52-84-125-92.iad16.r.cloudfront.net
August 18, 2016
server-52-84-125-80.iad16.r.cloudfront.net
August 18, 2016
server-52-84-125-77.iad16.r.cloudfront.net
August 18, 2016
server-52-84-125-205.iad16.r.cloudfront.net
August 3, 2016
server-52-84-125-201.iad16.r.cloudfront.net
August 3, 2016
server-52-84-125-148.iad16.r.cloudfront.net
August 3, 2016
server-52-84-125-120.iad16.r.cloudfront.net
August 3, 2016
server-52-84-125-96.iad16.r.cloudfront.net
August 3, 2016
server-52-84-125-37.iad16.r.cloudfront.net
August 3, 2016
server-52-84-125-20.iad16.r.cloudfront.net
August 3, 2016
server-52-84-125-227.iad16.r.cloudfront.net
August 3, 2016
server-52-84-125-47.iad16.r.cloudfront.net
July 17, 2016
server-52-84-125-44.iad16.r.cloudfront.net
July 17, 2016
server-52-84-125-215.iad16.r.cloudfront.net
July 17, 2016
server-52-84-125-210.iad16.r.cloudfront.net
July 17, 2016
server-52-84-125-196.iad16.r.cloudfront.net
July 17, 2016
server-52-84-125-126.iad16.r.cloudfront.net
July 17, 2016
Showing 30 of 86 IP Addresses
File downloads found at URLs served by www.sharecapitalclear.com.
The following 74 files have been seen to comunicate with www.sharecapitalclear.com in live environments.