dl2.vic9installer.com

NATIVEX HOLDINGS, LLC

Domain Information

The domain dl2.vic9installer.com registered by NATIVEX HOLDINGS, LLC was initially registered in January of 2014 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Wednesday, January 15, 2014

Expires date:
Thursday, January 15, 2015

Updated date:
Wednesday, August 20, 2014

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.InstallX.O, PUP.Installer.InstallX.I, PUP.Installer.InstallX.E, PUP.InstallX.SafeInstall.Installer (M), PUP.InstallX.SafeInst.Installer (M)
100.00%

MicroWorld eScan
Gen:Variant.Application.Bundler.Graftor.155902
88.89%

Malwarebytes
PUP.Optional.SafeInstall.A
88.89%

K7 AntiVirus
Unwanted-Program
88.89%

Trend Micro House Call
Suspicious_GEN.F47V1118, Suspicious_GEN.F47V1119, Suspicious_GEN.F47V1115, TROJ_GEN.F0C2C00LH14, Suspicious_GEN.F47V1120
88.89%

avast!
Win32:Adware-gen [Adw], Win32:PUP-gen [PUP], Adware-CFF [PUP]
88.89%

Kaspersky
not-a-virus:Downloader.NSIS.Agent
88.89%

Bitdefender
Gen:Variant.Application.Bundler.Graftor.155902
88.89%

NANO AntiVirus
Riskware.Win32.Searcher.csnymk
88.89%

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Graftor.155902
88.89%

Sophos
InstallQ, PUA 'InstallQ'
88.89%

Comodo Security
Application.Win32.InstallIQ.B
88.89%

F-Secure
Gen:Variant.Application.Bundler, Trojan.Downloader.JRJW
88.89%

Dr.Web
Adware.Downware.2512, Adware.Downware.9371, Threat.Undefined
88.89%

VIPRE Antivirus
InstallIQ Installer, Threat.4783689
88.89%

The domain dl2.vic9installer.com has been seen to resolve to the following 4 IP addresses.

unallocated.barefruit.co.uk
May 3, 2015

February 22, 2015

cdn-208-111-160-6.iad.llnw.net
November 29, 2014

cdn-208-111-161-254.iad.llnw.net
November 29, 2014

File downloads found at URLs served by dl2.vic9installer.com.

1 / 68      (Adware)

31 / 68    (Adware)

37 / 68    (Adware)

24 / 68    (Adware)

29 / 68    (Adware)

31 / 68    (Adware)

31 / 68    (Adware)

31 / 68    (Adware)

32 / 68    (Adware)

The following 315 files have been seen to comunicate with dl2.vic9installer.com in live environments.

 
Latest 20 of 365 files

URL:
http://dl2.vic9installer.com/

Title:
“Please Wait - You are being redirected.”

Web server:
nginx/1.0.15