dl2.vik9installer.com

NATIVEX HOLDINGS, LLC

Domain Information

The domain dl2.vik9installer.com registered by NATIVEX HOLDINGS, LLC was initially registered in August of 2014 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Limelight Networks, Inc. network.
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Tuesday, August 26, 2014

Expires date:
Wednesday, August 26, 2015

Updated date:
Monday, April 20, 2015

ASN:
AS22822 LLNW-AS Limelight Networks, INC. proxy AS object

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.InstallX.R, PUP.Installer.InstallX.J, PUP.Installer.InstallX.E, PUP.Installer.InstallX.Q, PUP.Installer.InstallX.O, PUP.InstallX.SafeInstall.Installer (M), PUP.InstallX.SafeInst.Installer (M), PUP.InstallX (M)
100.00%

MicroWorld eScan
Gen:Variant.Application.Bundler.Graftor.155902
64.29%

Malwarebytes
PUP.Optional.SafeInstall.A
64.29%

Zillya! Antivirus
Downloader.Agent.Win32.229676, Downloader.Agent.Win32.238160, Downloader.Agent.Win32.223881
64.29%

K7 AntiVirus
Unwanted-Program
64.29%

Trend Micro House Call
Suspicious_GEN.F47V1210, Suspicious_GEN.F47V1220, TROJ_GEN.F0C2C00KP14, Suspicious_GEN.F47V1224, TROJ_GEN.F0C2C00LS14, TROJ_GEN.F0C2C00LH14
64.29%

avast!
Win32:PUP-gen [PUP], Win32:Adware-gen [Adw]
64.29%

Kaspersky
not-a-virus:Downloader.NSIS.Agent
64.29%

Bitdefender
Gen:Variant.Application.Bundler.Graftor.155902
64.29%

NANO AntiVirus
Riskware.Win32.Searcher.csnymk
64.29%

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Graftor.155902
64.29%

Comodo Security
Application.Win32.InstallIQ.B
64.29%

F-Secure
Gen:Variant.Application.Bundler
64.29%

Dr.Web
Adware.Downware.2512, Adware.Downware.9371
64.29%

VIPRE Antivirus
InstallIQ Installer
64.29%

The domain dl2.vik9installer.com has been seen to resolve to the following 3 IP addresses.

May 2, 2015

cdn-208-111-160-6.iad.llnw.net
January 9, 2015

cdn-208-111-161-254.iad.llnw.net
January 9, 2015

File downloads found at URLs served by dl2.vik9installer.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

34 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

33 / 68    (Adware)

35 / 68    (Adware)

32 / 68    (Adware)

28 / 68    (Adware)

31 / 68    (Adware)

31 / 68    (Adware)

31 / 68    (Adware)

30 / 68    (Adware)

25 / 68    (Adware)

The following 86 files have been seen to comunicate with dl2.vik9installer.com in live environments.

 
Latest 20 of 136 files

URL:
http://dl2.vik9installer.com/

Google Analytics:
UA-2249740

Title:
“Vik9installer.com”

Description:
“Find Instyler, Windows Installer and more at Vik9installer.com. Get the best of Vuze Installer or Windows Installer Cleanup Utility, browse our section on Download Windows Installer or learn about Carpet Installers. Vik9installer.com is the site ...”

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)

30 of 685 related domains