dl2.cdn4-downloads.com

REACTIVATION PERIOD

Domain Information

The domain dl2.cdn4-downloads.com registered by REACTIVATION PERIOD was initially registered in October of 2010 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Limelight Networks, Inc. network.
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Tuesday, October 26, 2010

Expires date:
Monday, October 26, 2015

Updated date:
Tuesday, December 08, 2015

ASN:
AS22822 LLNW-AS Limelight Networks, INC. proxy AS object

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.InstallX.J, PUP.Installer.W3i.K, PUP.Installer.W3i.G, PUP.Installer.W3i.E, PUP.Installer.W3i.P, PUP.InstallX.W3i.Installer (M)
100.00%

Malwarebytes
PUP.Optional.InstallIQ, PUP.Optional.InstallIQ.A
50.00%

Dr.Web
Adware.W3i.32, Adware.W3i.8
50.00%

VIPRE Antivirus
InstallIQ Installer, Threat.4150696
50.00%

Avira AntiVirus
APPL/InstallIQ.Gen5
50.00%

ESET NOD32
Win32/InstallIQ (variant)
50.00%

Rising Antivirus
PE:PUF.InstallIQ!1.9E4F
50.00%

Trend Micro House Call
TROJ_GEN.F47V0404, TROJ_GEN.F47V0101, TROJ_GEN.F47V1231, Mal_Naix-5
41.67%

Comodo Security
Application.Win32.InstallIQ.B, UnclassifiedMalware
33.33%

Boost by Reason
Optional.InstallX.J, Optional.W3i.K
33.33%

Baidu Antivirus
Trojan.Win32.InstallIQ, Trojan.Win32.Agent
33.33%

avast!
Win32:Malware-gen
25.00%

Sophos
InstallQ, InstallIQ
25.00%

NANO AntiVirus
Riskware.Win32.Searcher.csnymk
16.67%

AVG
MalSign.Generic
16.67%

The domain dl2.cdn4-downloads.com has been seen to resolve to the following 4 IP addresses.

cdn-208-111-160-6.iad.llnw.net
September 5, 2014

cdn-208-111-161-254.iad.llnw.net
September 5, 2014

April 11, 2014

April 11, 2014

File downloads found at URLs served by dl2.cdn4-downloads.com.

1 / 68      (Adware)
http://dl2.cdn4-downloads.com/lm/.../epicbot_520.exe  (af03247d654437791af978c32bf25194)

2 / 68      (Adware)
http://dl2.cdn4-downloads.com/lm/.../jenkatarcade.exe  (cd6e6f416e4cf62efadb30c9c7780570)

1 / 68      (Adware)
http://dl2.cdn4-downloads.com/lm/.../whales.exe  (cbaa93868ac42dc7b8ad8a1f8f27d8cd)

1 / 68      (Adware)
http://dl2.cdn4-downloads.com/lm/.../wfallsaw.exe  (28f861c47a0abc223bc6ef76ff190311)

9 / 68      (Adware)
http://dl2.cdn4-downloads.com/lm/.../musicoasis.exe  (ecfe60c9ffe9220a8124bc21ee48df88)

11 / 68    (Adware)
http://dl2.cdn4-downloads.com/lm/.../musicoasis.exe  (7eeefb7a165a4bc99e9ed67fc0f38520)

1 / 68      (Adware)

15 / 68    (Adware)
http://dl2.cdn4-downloads.com/lm/.../musicoasis.exe  (b809e40101d215f374b44a529c5900a8)

1 / 68      (Adware)
http://dl2.cdn4-downloads.com/lm/.../7Zip.exe  (ba2be508172b47b48c3e20485b95d392)

16 / 68    (Adware)
http://dl2.cdn4-downloads.com/lm/.../VLC_32.exe  (b1ab0ab1cfb050ba756692c2387a7269)

17 / 68    (Adware)

17 / 68    (Adware)

The following 150 files have been seen to comunicate with dl2.cdn4-downloads.com in live environments.

 
Latest 20 of 292 files