dl2.vic5installer.com

InstallX, LLC

Domain Information

The domain dl2.vic5installer.com registered by NATIVEX HOLDINGS, LLC was initially registered in January of 2014 through ENOM, INC.. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Limelight Networks, Inc. network. The domain is associated with the publisher InstallX, LLC who is located in Sartell, Minnesota in the United States.
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Thursday, January 02, 2014

Expires date:
Saturday, January 02, 2016

Updated date:
Monday, April 20, 2015

ASN:
AS22822 LLNW-AS Limelight Networks, INC. proxy AS object

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.SecureInstall.K, PUP.Installer.SecureInstall.G, PUP.Installer.SecureInstall.F, PUP.Installer.SecureInstall.L, PUP.InstallX.SecureInstall.Installer (M), PUP.InstallX.SecureIn.Installer (M), PUP.InstallX (M)
100.00%

Malwarebytes
PUP.Optional.SafeInstall, PUP.Optional.SafeInstall.A
88.89%

NANO AntiVirus
Riskware.Win32.Searcher.cjaztx, Riskware.Win32.Searcher.csnymk
88.89%

Dr.Web
Adware.Searcher.2593, Adware.Downware.2512
88.89%

VIPRE Antivirus
InstallIQ Installer
88.89%

ESET NOD32
Win32/InstallIQ (variant)
88.89%

Rising Antivirus
PE:PUF.InstallIQ!1.9E4F
88.89%

McAfee
Artemis!158533E973EF, PUP-FLX, Artemis!EC55C10C057A, Artemis!C8F1EB982D37, Artemis!541EC320D4A6, Artemis!25CCAE59E743, Artemis!9B0EF7D18E01, Artemis!730D6BDC18F5, Artemis!D4907BF85008
77.78%

Trend Micro House Call
TROJ_GEN.F47V0118, TROJ_GEN.F47V0208, TROJ_GEN.F47V0205, TROJ_GEN.F47V0130, TROJ_GEN.F47V0207, TROJ_GEN.F47V0124, TROJ_GEN.F47V0411
77.78%

McAfee Web Gateway
Artemis!158533E973EF, PUP-FLX, Artemis!EC55C10C057A, Artemis!C8F1EB982D37, Artemis!541EC320D4A6, Artemis!25CCAE59E743, Artemis!9B0EF7D18E01
77.78%

Sophos
DomainIQ pay-per install
77.78%

AVG
Generic_r, MultiBundle, InstallIQ
66.67%

G Data
Win32.Application.InstallIQ
61.11%

Agnitum Outpost
Riskware.Agent
55.56%

K7 Gateway Antivirus
Unwanted-Program
44.44%

The domain dl2.vic5installer.com has been seen to resolve to the following 5 IP addresses.

May 3, 2015

cdn-208-111-161-254.iad.llnw.net
March 15, 2014

cdn-208-111-160-6.iad.llnw.net
March 15, 2014

January 17, 2014

January 17, 2014

File downloads found at URLs served by dl2.vic5installer.com.

1 / 68      (Adware)

1 / 68      (Adware)

36 / 68    (Adware)

28 / 68    (Adware)

9 / 68      (Adware)

28 / 68    (Adware)

28 / 68    (Adware)

28 / 68    (Adware)

34 / 68    (Adware)

27 / 68    (Adware)

28 / 68    (Adware)

12 / 68    (Adware)

28 / 68    (Adware)

28 / 68    (Adware)

27 / 68    (Adware)

28 / 68    (Adware)

28 / 68    (Adware)

28 / 68    (Adware)

7 / 68      (Adware)

The following 150 files have been seen to comunicate with dl2.vic5installer.com in live environments.

 
Latest 20 of 292 files

URL:
http://dl2.vic5installer.com/

Google Analytics:
UA-2249740

Title:
“Vic5installer.com”

Description:
“Find Instyler, Windows Installer and more at Vic5installer.com. Get the best of Vuze Installer or Windows Installer Cleanup Utility, browse our section on Download Windows Installer or learn about Carpet Installers. Vic5installer.com is the site ...”

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)

30 of 692 related domains