dl2.iq2download.com

China Capital Investment Limited

Domain Information

The domain dl2.iq2download.com registered by China Capital Investment Limited was initially registered in June of 2015 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Limelight Networks, Inc. network.
Registrar:
DOMAINGAZELLE.COM LLC

Server location:
Virginia, United States (US)

Create date:
Saturday, June 06, 2015

Expires date:
Monday, June 06, 2016

Updated date:
Monday, March 07, 2016

ASN:
AS22822 LLNW-AS Limelight Networks, INC. proxy AS object

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.W3i.U, PUP.Installer.InstallX.J, PUP.Installer.W3i.I, PUP.Installer.W3i.V, PUP.Installer.W3i.K, PUP.InstallX.W3i.Installer (M)
94.74%

Dr.Web
Adware.W3i.3, Adware.W3i.32, Adware.W3i.9, probably STPAGE.Trojan
68.42%

VIPRE Antivirus
InstallIQ Installer, Trojan.Win32.Generic, Threat.4783689
57.89%

Malwarebytes
PUP.Optional.InstallIQ, PUP.Optional.InstallIQ.A
52.63%

Avira AntiVirus
APPL/InstallIQ.Gen5
52.63%

ESET NOD32
Win32/InstallIQ (variant)
52.63%

Comodo Security
Application.Win32.InstallIQ.B, UnclassifiedMalware, Application.Win32.InstallIQ.NTZK
42.11%

Trend Micro House Call
TROJ_GEN.F47V0404, TROJ_GEN.R047H0AJL13, HV_ZYX_CA224FC7.TOMC, TROJ_GEN.RC1H1EJ, TROJ_GEN.RC1H1CD
36.84%

McAfee Web Gateway
Artemis!FBBB700F3F06, Artemis!F008A5420B73, BehavesLike.Win32.Obfuscated.th
36.84%

Baidu Antivirus
Trojan.Win32.InstallIQ, Adware.Win32.InstallIQ, Trojan.Win32.Agent
36.84%

G Data
Win32.Trojan.Agent.826A5G, Win32.Application.InstallIQ
31.58%

Rising Antivirus
PE:PUF.InstallIQ!1.9E4F
26.32%

K7 AntiVirus
Unwanted-Program
26.32%

K7 Gateway Antivirus
Unwanted-Program
26.32%

Fortinet FortiGate
Adware/InstallIQ
26.32%

The domain dl2.iq2download.com has been seen to resolve to the following 8 IP addresses.

July 19, 2016

April 13, 2016

July 26, 2015

November 10, 2014

April 11, 2014

April 11, 2014

cdn-208-111-160-6.iad.llnw.net
March 19, 2014

cdn-208-111-161-254.iad.llnw.net
March 19, 2014

File downloads found at URLs served by dl2.iq2download.com.

1 / 68      (Adware)

3 / 68      (PUP)
http://dl2.iq2download.com/lm/.../VLC_32.exe  (b4eca1204e5fc08bc76c220d76aa6024)

1 / 68      (Adware)
http://dl2.iq2download.com/lm/.../amazinguniversess.exe  (47e914b7b32f7455293041a69404237b)

1 / 68      (Adware)
http://dl2.iq2download.com/lm/.../facepaint.exe  (e178bb6839d010e2f81e24c9ed965be2)

15 / 68    (Adware)
http://dl2.iq2download.com/lm/.../ezcalendar.exe  (54e425bd473c379cdbedd88a2efea705)

1 / 68      (Adware)
http://dl2.iq2download.com/lm/.../abiword.exe  (cb83562c5200314a34723523ac250143)

1 / 68      (Adware)
http://dl2.iq2download.com/lm/.../intunemp3.exe  (8fe24096d9482109b651357045c90da4)

12 / 68    (Adware)
http://dl2.iq2download.com/lm/.../playalotgames.exe  (1c44a044a6a513b8fc189049d64b0911)

13 / 68    (Adware)
http://dl2.iq2download.com/lm/.../gimpts_542.exe  (3eeb486f27d4709d18bd5f8f2f7ccb59)

12 / 68    (Adware)
http://dl2.iq2download.com/lm/.../butterflies.exe  (460e107d22e7c6865347fcbf17d08471)

15 / 68    (Adware)
http://dl2.iq2download.com/lm/.../bitzipper_513.exe  (e5c951bd55777bf27cb7e3e7c207ab70)

13 / 68    (Adware)
http://dl2.iq2download.com/lm/.../musicoasis.exe  (7fb996fa200e42ce3ecd900e48e12745)

27 / 68    (Adware)
http://dl2.iq2download.com/lm/.../musicoasis.exe  (d9fc372c2d5d98f7531878e2b0d8bfd6)

1 / 68      (Adware)

2 / 68      (Adware)
http://dl2.iq2download.com/lm/.../7Zip_966.exe  (5a79bd2c786e2e4e2863703a927c4cde)

17 / 68    (Adware)

17 / 68    (Adware)

17 / 68    (Adware)

2 / 68      (Adware)

The following 155 files have been seen to comunicate with dl2.iq2download.com in live environments.

 
Latest 20 of 297 files

URL:
http://dl2.iq2download.com/

Web server:
nginx/1.8.1