212link.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain 212link.com is registered by proxy through GODADDY.COM, LLC and was originally registered in January of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Thursday, January 31, 2013

Expires date:
Tuesday, January 31, 2017

Updated date:
Friday, February 5, 2016

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Amonetizeltd.d, PUP.Awimba.W, PUP.Installer.OptimumInstaller.G, PUP.Installer.InstallX.H, DownloadManager.Air Software, PUP.Adknowledge.OptimumInstaller.Installer (M), PUP.Tuguu.Awimba.Bundler (M), PUP.Air Software.AirSoftware.Bundler (M), PUP.Adknowledge.OptimumI.Bundler (M), PUP.Air Software.AirSoftw.Bundler (M), PUP.Air Software.Download.Bundler (M), PUP.Air Software (M), PUP.Adknowledge (M)
100.00%

Dr.Web
Adware.Downware.1528, Adware.W3i.29, Adware.Downware.1246, Adware.W3i.25, Trojan.SMSSend.4554, Trojan.SMSSend.4543, Adware.Downware.10718
40.63%

VIPRE Antivirus
Amonetize, DomaIQ, Threat.4778314, InstallIQ Installer, AirInstaller, Threat.4150696, Threat.4782985
40.63%

Avira AntiVirus
ADWARE/Adware.Gen2, APPL/DomaIQ.Gen, Adware/iBryte.amhy, APPL/InstallIQ.Gen5, TR/Zusy.bmjkonyb, ADWARE/Adware.Gen7, Adware/Agent.aece.3
40.63%

Sophos
Amonetize, DomainIQ pay-per install, iBryte Optimum Installer, InstallQ, PUA 'AirInstaller'
40.63%

avast!
Win32:Amonetize-I [PUP], MSIL:DomaIQ-F [PUP], Win32:PUP-gen [PUP], Win32:Installer-J [PUP], Win32:Adware-CAH [PUP]
37.50%

AVG
MalSign.Generic, Skodna.Bundle, DomaIQ, Potentially harmful program Skodna.Downloader, Adware Generic_r.IZ, Adware Generic_r.JA
37.50%

Comodo Security
Application.Win32.Downloader.Agent.WA, Application.Win32.DomaIq.~A, ApplicUnwnt.Win32.AdWare.iBryte.H, Application.Win32.InstallIQ.B
37.50%

Malwarebytes
PUP.Optional.Amonetize.A, Adware.DomaIQ, PUP.Optional.Ibryte, PUP.Optional.InstallIQ, PUP.Optional.AirInstaller
34.38%

K7 AntiVirus
Unwanted-Program , Trojan , Adware
34.38%

Vba32 AntiVirus
Downloader.Agent, SScope.Adware.OptimusInstaller.26607, AdWare.AirAdInstaller
34.38%

NANO AntiVirus
Trojan.Win32.W3i.bmejvi, Riskware.Base64.DomaIQ.cwpnap, Riskware.Win32.Agent.cssrke, Riskware.Win32.AirAdInstaller.cwfgei
34.38%

G Data
Adware.Downloadware.AK, Win32.Application.DomalQ, Win32.Adware.Ibryte, Win32.Adware.Airadinstaller, Win32.Adware.OptimumInst
34.38%

MicroWorld eScan
Adware.Downloadware.AK, Application.Generic.526895, Gen:Variant.Adware.Graftor.145568, Application.Bundler.AirInstaller.E
31.25%

Bitdefender
Adware.Downloadware.AK, Application.Generic.526895, Gen:Variant.Adware.Graftor.145568, Application.Bundler.AirInstaller.E
31.25%

The domain 212link.com has been seen to resolve to the following 4 IP addresses.

July 13, 2016

June 19, 2016

ec2-54-72-9-51.eu-west-1.compute.amazonaws.com
June 5, 2016

ip-184-168-221-63.ip.secureserver.net
April 19, 2016

File downloads found at URLs served by 212link.com.

1 / 68      (Adware)

The following 299 files have been seen to comunicate with 212link.com in live environments.

 
Latest 20 of 307 files

URL:
http://212link.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)