dl2.iq8download.com

InstallX, LLC

Domain Information

The domain dl2.iq8download.com registered by Whois Privacy Shield Services was initially registered in February of 2016 through ENOM, INC.. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States. The domain uses the Amazon Web Services (AWS) cloud computing platform. The domain is associated with the publisher InstallX, LLC who is located in Sartell, Minnesota in the United States.
Registrar:
LEONIDAS, LLC

Server location:
Virginia, United States (US)

Create date:
Thursday, February 11, 2016

Expires date:
Saturday, February 11, 2017

Updated date:
Sunday, February 14, 2016

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.W3i.S, PUP.Installer.W3i.M, PUP.Installer.InstallX.J, PUP.Installer.W3i.W, PUP.Installer.W3i.J, PUP.Installer.W3i.R, PUP.InstallX.W3i.Installer (M), PUP.InstallX (M)
100.00%

Dr.Web
Adware.W3i.9, Adware.Downware.888, Adware.W3i.32, Adware.W3i.4
75.00%

Avira AntiVirus
APPL/InstallIQ.Gen5, Adware/InstallC.B.1
75.00%

Malwarebytes
PUP.Optional.InstallIQ.A
72.73%

Trend Micro House Call
TROJ_FAKEAV.BMC, TROJ_GEN.R0CBH0ABF14, TROJ_GEN.F47V0406, TROJ_GEN.F47V0404, TROJ_SPNR.0CA214, TROJ_GEN.R0CBB01J713, TROJ_GEN.R00JH0ALJ13
72.73%

VIPRE Antivirus
InstallIQ Installer
72.73%

ESET NOD32
Win32/InstallIQ (variant)
72.73%

Comodo Security
UnclassifiedMalware, Application.Win32.InstallIQ.B, Application.Win32.InstallIQ.NTZK
65.91%

Sophos
InstallQ
61.36%

Rising Antivirus
PE:PUF.InstallIQ!1.9E4F, PE:Trojan.Win32.Generic.137215B6!326243766, PE:Trojan.Win32.Generic.133DA0DB!322805979
56.82%

AVG
AdInstaller.InstallQ, MalSign.Generic
54.55%

McAfee
Artemis!132905E8A5FF, Artemis!81728D8CF5BF, Artemis!FBBB700F3F06, Artemis!E1BBC72B7F02, Artemis!772480DBD233, Artemis!B5447BCB0398, Artemis!AAEB3C2BCD92, Artemis!2F629240C572, Artemis!77B8FD7A3574
54.55%

McAfee Web Gateway
Artemis!132905E8A5FF, Artemis!81728D8CF5BF, Artemis!FBBB700F3F06, Artemis!E1BBC72B7F02, Artemis!772480DBD233, Artemis!B5447BCB0398
54.55%

IKARUS anti.virus
AdWare.Win32.InstallIQ, Win32.Malware, AdWare.InstallC, Win32.AdWare
54.55%

MicroWorld eScan
APPL/InstallIQ.Gen5, Win32/InstallIQ, Adware/InstallC.B.1
50.00%

The domain dl2.iq8download.com has been seen to resolve to the following 7 IP addresses.

125.34.148.146.bc.googleusercontent.com
February 21, 2016

ec2-54-210-47-225.compute-1.amazonaws.com
February 21, 2016

May 5, 2015

cdn-208-111-160-6.iad.llnw.net
September 27, 2014

cdn-208-111-161-254.iad.llnw.net
September 27, 2014

April 11, 2014

April 11, 2014

File downloads found at URLs served by dl2.iq8download.com.

18 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl2.iq8download.com/lm/.../clipartcollection.exe  (cadb8f3faee9d1e90df7dfb31ba2d882)

1 / 68      (Adware)
http://dl2.iq8download.com/lm/.../waterfalls3.exe  (91126b21f433b57e73f16bfe175c0d03)

1 / 68      (Adware)

24 / 68    (Adware)
http://dl2.iq8download.com/lm/.../epicbot.exe  (16a91f721a502aaf4e9011b783daf519)

17 / 68    (Adware)

1 / 68      (Adware)

15 / 68    (Adware)

1 / 68      (Adware)

31 / 68    (Adware)
http://dl2.iq8download.com/lm/.../freefileviewer_730.exe  (48bfabdefa16fbef2b85b834a28e4d59)

10 / 68    (Adware)

13 / 68    (Adware)
http://dl2.iq8download.com/lm/.../mplayer_tuguu_1271.exe  (f631b96f54584ccbdfde037cca81f3a9)

1 / 68      (Adware)
http://dl2.iq8download.com/lm/.../musicrockstar.exe  (c543c187308831cde5e57c9c08d831f7)

1 / 68      (Adware)
http://dl2.iq8download.com/lm/.../waterfalls1aw.exe  (5efb7077689f38e3a4413bbae0adc6e1)

31 / 68    (Adware)
http://dl2.iq8download.com/lm/.../tvshows.exe  (5ff5b5bf5beca2ecbfe736a9dd9e0392)

1 / 68      (Adware)
http://dl2.iq8download.com/lm/.../cabin.exe  (d41872a459c854222aef60aa81b99c5c)

14 / 68    (Adware)

36 / 68    (Adware)
http://dl2.iq8download.com/lm/.../musicoasis.exe  (78b2afacb542703ff5abf5d7656e0686)

1 / 68      (Adware)

31 / 68    (Adware)

9 / 68      (Adware)
http://dl2.iq8download.com/lm/.../fbdownloader.exe  (ecf6c624b154fa746b249d635d7f70cd)

29 / 68    (Adware)
http://dl2.iq8download.com/lm/.../bitzipper_513.exe  (0ef2e88d270039eea754539018bef407)

29 / 68    (Adware)
http://dl2.iq8download.com/lm/.../openfreely_1296.exe  (b5447bcb0398d70962715e31fa10b507)

1 / 68      (Adware)

18 / 68    (Adware)
http://dl2.iq8download.com/lm/.../nuancepdf.exe  (e1bbc72b7f02bf9eae805d4cab9dfad5)

18 / 68    (Adware)

15 / 68    (Adware)
http://dl2.iq8download.com/lm/.../mplayer_tuguu.exe  (432edf19bab70081c41fddf49d51a533)

 
Latest 30 of 44 download URLs

The following 155 files have been seen to comunicate with dl2.iq8download.com in live environments.

 
Latest 20 of 300 files

URL:
http://dl2.iq8download.com/

Google Analytics:
UA-48689684

Title:
“iq8download.com”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx

30 of 631 related domains