cdn.offers.multiinstall.com

Corp New Ventures Services

Domain Information

The domain cdn.offers.multiinstall.com registered by Corp New Ventures Services was initially registered in May of 2016 through RALLY CRY DOMAINS, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Road Town, British Virgin Islands within VG which resides on the Confluence Networks Inc network.
Registrar:
RALLY CRY DOMAINS, LLC

Server location:
British Virgin Islands, VG (VG)

Create date:
Sunday, May 8, 2016

Expires date:
Monday, May 8, 2017

Updated date:
Sunday, May 15, 2016

ASN:
AS40034 CONFLUENCE-NETWORK-INC - Confluence Networks Inc,VG

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.UnilogicInformaticaaME.a, PUP.Installer.UnilogicInformaticaaME.d, PUP.Installmatic.Unilogic.Installer (M)
100.00%

avast!
Win32:Downloader-TQT [PUP]
28.57%

ESET NOD32
Win32/Hao123 (variant), Win32/InstallBrain.AQ (variant)
28.57%

K7 AntiVirus
Riskware
14.29%

Trend Micro House Call
TROJ_GEN.F47V0510
14.29%

Sophos
Generic PUA HB
14.29%

Baidu Antivirus
Trojan.Win32.StartPage
14.29%

IKARUS anti.virus
Trojan.Win32.StartPage
14.29%

AVG
MalSign.Generic
14.29%

Dr.Web
Adware.Downware.1425
14.29%

Avira AntiVirus
APPL/InstallBrain.Gen
14.29%

The domain cdn.offers.multiinstall.com has been seen to resolve to the following IP address.

May 18, 2016

File downloads found at URLs served by cdn.offers.multiinstall.com.

9 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

5 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

The following 2 files have been seen to comunicate with cdn.offers.multiinstall.com in live environments.

URL:
http://cdn.offers.multiinstall.com/

Web server:
Apache