cdn.install.oibundles2.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain cdn.install.oibundles2.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in San Jose, California within the United States which resides on the CDNetworks Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
California, United States (US)

Create date:
Thursday, March 29, 2012

Expires date:
Wednesday, March 29, 2017

Updated date:
Monday, February 8, 2016

ASN:
AS36408 CDNETWORKSUS-02 CDNetworks Inc.

Root domain:

Scanner detections:
Detections  (60% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.betwikx.EE, PUP.BrowserSetter.N, PUP.ShetefSolutionsConsulting1998.O, PUP.ShetefSolutionsConsulting1998.M, PUP.ShetefSolutionsConsulting1998.N, PUP.Installer.BrandAffinityTechnologies.M, PUP.DealPly.C, PUP.custominstaller.Conduit.L, PUP.Optional.FreeCause.Z
68.42%

Trend Micro House Call
TROJ_GE.73AB5BC3, TROJ_GEN.RCBH1BP, TROJ_GEN.FCBCBLA, TROJ_SPNR.0BHN12, TROJ_GEN.RCBH1BJ, TROJ_FAKEALERT.BMH, TROJ_GEN.RCBH1KQ, ADW_IBRYTE
55.26%

Dr.Web
Adware.Shopper.297, Trojan.AVKill.23908, Trojan.MulDrop5.267, Trojan.AVKill.19520, Adware.Funmoods.1, Trojan.PWS.Siggen.36406, Adware.FreeCause.3
52.63%

ESET NOD32
Win32/Adware.Moonshle (variant), Win32/Amonetize, Win32/Agent.TXC, Win32/Toolbar.Funmoods (variant), Win32/Toolbar.CrossRider
47.37%

VIPRE Antivirus
Pinball Corporation, Trojan.Win32.Generic, Trojan.Win32.Generic!SB.0, Adware.Adpeak, GamePlayLabs, Sweetpacks/SweetIM, Babylon
36.84%

McAfee
Artemis!A066B331A620, Artemis!9DB0C28D55C1, Artemis!D58ECE42554D, Artemis!21AD8A07C37C, Artemis!7703B52FBBC2, Artemis!6D982AFCD658, Artemis!39E497A1D4D0, Artemis!11A6A5E4EF24, Artemis!4E3529F98374
31.58%

Boost by Reason
Adware.betwikx.EE, Adware.AdPeak.J, Optional.ExcellentApps.T, Optional.SweetIM.S, Adware.Installer.Babylon.K, PUP.FreeCause.Z, Trojan.Adw.PriceGong.S, Optional.DealPly.K, Adware.W3i.AA
28.95%

Malwarebytes
PUP.Optional.PricePeep.A, Trojan.Startpage, Adware.BrowserCompanion, PUP.215Apps, PUP.Optional.SweetIM, PUP.Optional.Babylon.A
26.32%

Comodo Security
UnclassifiedMalware, Heur.Suspicious, ApplicUnwnt
21.05%

MicroWorld eScan
Adware.PricePeep.A, Trojan.Generic.8374794, Dropped:Trojan.Generic.7847666, Trojan.Crypt, Trojan-Dropper.Agent, Win32/Adware.JIQDSWX
18.42%

avast!
Win32:Malware-gen, NSIS:Dropper-GM [Drp], Win32:Downloader-SZW [PUP], Win32:DealPly-A [PUP]
18.42%

Emsisoft Anti-Malware
Adware.PricePeep, Dropped:Trojan.Generic.7847666, Riskware.Win32.Toolbar.Babylon.AMN, Adware.Win32.PriceGong.AMN, Adware.Win32.FCVRETQ.AMN
15.79%

Avira AntiVirus
TR/Rogue.8374794, TR/Agent.578688.1, TR/Trash.Gen, TR/Agent.1513252, ADWARE/Yontoo.Gen2, ADWARE/Adware.Gen
15.79%

IKARUS anti.virus
Trojan.SuspectCRC, Trojan.Win32.Webprefix, Trojan-Ransom.Win32.Foreign, Trojan-Dropper.Agent, AdWare.Yontoo
15.79%

Panda Antivirus
Trj/CI.A, Generic Malware, Trj/Dtcontx.B, Suspicious file, Adware/Conduit
15.79%

The domain cdn.install.oibundles2.com has been seen to resolve to the following 6 IP addresses.

November 16, 2013

November 16, 2013

November 16, 2013

November 16, 2013

November 16, 2013

November 16, 2013

File downloads found at URLs served by cdn.install.oibundles2.com.

1 / 68      (PUP)

10 / 68    (Adware)
http://cdn.install.oibundles2.com/bundles/.../dp.exe  (c341fe87d7714655245b7bd8e13edb45)

9 / 68      (PUP)

6 / 68      (PUP)

0 / 68
http://cdn.install.oibundles2.com/bundles/.../AbiWord.exe  (5d04d875f415062f8babd49656ff7d3a)

6 / 68      (PUP)

2 / 68      (Adware)

8 / 68      (Adware)

5 / 68      (Adware)

5 / 68      (PUP)

4 / 68      (PUP)

7 / 68      (Adware)

1 / 68      (PUP)

8 / 68      (Adware)

7 / 68      (Adware)
http://cdn.install.oibundles2.com/bundles/.../jetmp3.exe  (6400ee4c3e0e033cd9fed31805828a44)

18 / 68    (Adware)

5 / 68      (PUP)

9 / 68      (Adware)

0 / 68

2 / 68      (PUP)

13 / 68    (PUP)

19 / 68    (Adware)

7 / 68      (Adware)

13 / 68    (Adware)

8 / 68      (Adware)

3 / 68      (inconclusive)

0 / 68

 
Latest 30 of 57 download URLs