dl8.iq8download.com

InstallX, LLC

Domain Information

The domain dl8.iq8download.com registered by Whois Privacy Shield Services was initially registered in February of 2016 through ENOM, INC.. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States. The domain uses the Amazon Web Services (AWS) cloud computing platform. The domain is associated with the publisher InstallX, LLC who is located in Sartell, Minnesota in the United States.
Registrar:
LEONIDAS, LLC

Server location:
Virginia, United States (US)

Create date:
Thursday, February 11, 2016

Expires date:
Saturday, February 11, 2017

Updated date:
Sunday, February 14, 2016

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.InstallX.T, PUP.Installer.W3i.W, PUP.Installer.W3i.U, PUP.Installer.W3i.L, PUP.Installer.InstallX.S, PUP.Installer.W3i.P, PUP.InstallX.Installer (M), PUP.InstallX.W3i.Installer (M), PUP.InstallX.W3i (M), PUP.InstallX (M)
100.00%

ESET NOD32
Win32/InstallIQ (variant), Win32/InstallIQ.A potentially unwanted (variant)
59.09%

Avira AntiVirus
Adware/InstallIQ.N, APPL/InstallIQ.Gen5, APPL/InstallIQ.J, TR/Trash.Gen, Adware/InstallC.B.1
56.82%

Dr.Web
Adware.W3i.32, Adware.W3i.9, Adware.W3i.25, Trojan.Domaiq.202, Trojan.Damaged.1
54.55%

Sophos
InstallQ
52.27%

VIPRE Antivirus
InstallIQ Installer, Trojan.Win32.Generic
52.27%

Comodo Security
Application.Win32.InstallIQ.B, UnclassifiedMalware, Application.Win32.InstallIQ.NTZK
50.00%

Malwarebytes
PUP.PlayPickle, PUP.Optional.InstallIQ.A
45.45%

Trend Micro House Call
TROJ_GEN.F47V0815, TROJ_FAKEAV.BMC, TROJ_GEN.FCBCBLA, TROJ_SPNR.0CJS13, TROJ_GEN.F47V0410, TROJ_GEN.F47V0120, TROJ_GEN.F47V0117, TROJ_GEN.F47V0305
34.09%

K7 AntiVirus
Riskware, Unwanted-Program
31.82%

MicroWorld eScan
Adware.InstallIQ.B, APPL/InstallIQ.Gen5
31.82%

Rising Antivirus
PE:PUF.InstallIQ!1.9E4F, PE:Trojan.Win32.Generic.1585D070!361091184, PE:Trojan.Win32.Generic.14A41BA7!346299303
25.00%

Fortinet FortiGate
Adware/Fam.NB, Adware/InstallIQ, W32/Itibiti.KNC!tr, W32/SPNR.0BA913!tr, Riskware/InstallIQ
25.00%

McAfee
Artemis!A34F9AC02DB1, Artemis!D8FA10DDD56E, Artemis!2AA9231B01A2, Artemis!132905E8A5FF, Artemis!7D5B48C0E03E, Artemis!497123CD3CDC
22.73%

AVG
Skodna.Generic_r, AdInstaller.InstallQ, InstallIQ
22.73%

The domain dl8.iq8download.com has been seen to resolve to the following 4 IP addresses.

ec2-54-210-47-225.compute-1.amazonaws.com
February 20, 2016

125.34.148.146.bc.googleusercontent.com
February 20, 2016

May 3, 2015

July 22, 2013

File downloads found at URLs served by dl8.iq8download.com.

1 / 68      (Adware)
http://dl8.iq8download.com/lm/.../games.exe  (4cc41270a9170b18f58a64f54ba16890)

1 / 68      (Adware)
http://dl8.iq8download.com/lm/.../cabin.exe  (4a380a856c02ae6071a9b398b7e38231)

18 / 68    (Adware)

26 / 68    (Adware)

12 / 68    (Adware)

14 / 68    (Adware)

9 / 68      (Adware)

20 / 68    (Adware)

10 / 68    (Adware)
http://dl8.iq8download.com/lm/.../musicoasis.exe  (77a314b4a39531c678c8a76e8da36c0f)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl8.iq8download.com/lm/.../livingsnowglobeswp1.exe  (28fbb57a61820b87f01a609cb2ef6d26)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl8.iq8download.com/lm/.../musicpig.exe  (6ec124ad8461ac5db7704874ab450f9a)

1 / 68      (Adware)

1 / 68      (Adware)
http://dl8.iq8download.com/lm/.../littleppt.exe  (7663f56e2aea1f0a87f087325d05c760)

1 / 68      (Adware)

8 / 68      (Adware)

11 / 68    (Adware)

11 / 68    (Adware)

4 / 68      (Adware)

12 / 68    (Adware)

9 / 68      (Adware)

16 / 68    (Adware)

1 / 68      (Adware)

6 / 68      (Adware)

23 / 68    (Adware)

 
Latest 30 of 435 download URLs

The following 6 files have been seen to comunicate with dl8.iq8download.com in live environments.

URL:
http://dl8.iq8download.com/

Google Analytics:
UA-48689684

Title:
“iq8download.com”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx

30 of 631 related domains