downloads.installationsafe.net

1&1 Internet Inc. - www.1and1.com

Domain Information

The domain downloads.installationsafe.net registered by 1&1 Internet Inc. - www.1and1.com was initially registered in April of 2013 through 1 & 1 INTERNET AG. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Remove Malware from downloads.installationsafe.net - Powered by Reason Core Security
Registrar:
1 & 1 INTERNET AG

Server location:
Virginia, United States (US)

Create date:
Tuesday, April 16, 2013

Expires date:
Saturday, April 16, 2016

Updated date:
Friday, April 17, 2015

ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.,US

Google Safe Browsing:
malware

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.InstallationSafe.V, PUP.Optional.Installer.I, PUP.Optional.Installer.F, PUP.Installer.InstallationSafe.F, PUP.Installer.DigitalPluginSL.F, PUP.Installer.InstallationSafe.S, PUP.AdGazelle.V, Threat.Installer.InstallationSafe, PUP.InstallationSafe (M), PUP.InstallationSafe.Installer (M), PUP.InstallCore.Installer.Installer (M), PUP.AdGazelle.Installer (M)
98.00%

K7 AntiVirus
Unwanted-Program , Trojan
42.00%

avast!
Adware-gen [Adw], Win32:Malware-gen, Win32:SoftPulse-AH [PUP], Win32:Trojan-gen, Rootkit-gen [Rtk], PUP-gen [PUP], Win32:Rootkit-gen [Rtk]
40.00%

K7 Gateway Antivirus
Unwanted-Program , Dialer , Trojan
40.00%

Avira AntiVirus
ADWARE/Adware.Gen2, Adware/Zusy.107390.2, Adware/AdGazelle.A, PUA/InstallCore.IY
40.00%

VIPRE Antivirus
Threat.5063330, Threat.4783235, Threat.4150696, Trojan.Win32.Generic, InstallCore
38.00%

Dr.Web
Adware.Downware.3941, Program.Unwanted.74, Trojan.MulDrop5.40191, Adware.Downware.9463, Adware.Downware.10558, Adware.Downware.9463
38.00%

McAfee
PUP-FLN, Socrydo, Program.PUP-FLN
38.00%

McAfee Web Gateway
PUP-FLN, BehavesLike.Win32.StartPage.jc, BehavesLike.Win32.MPlug.tc, BehavesLike.Win32.Sality.jc, BehavesLike.Win32.YahLover.jc
38.00%

G Data
Gen:Variant.Adware.AdGazelle, Gen:Variant.Adware.Zusy.107390, NSIS.Adware.AdGazelle, Gen:Variant.Adware.Strictor.67719, Win32.Application.AdGazelle
36.00%

ESET NOD32
Win32/AdGazelle.A potentially unwanted application, Win32/SoftPulse.O potentially unwanted application
34.00%

Agnitum Outpost
Riskware.Agent
34.00%

IKARUS anti.virus
PUA.AdGazelle, not-a-virus:AdWare.Agent, Win32.SuspectCrc
32.00%

Sophos
InstallationSafe, Install Core Click run software, SoftPulse, PUA 'InstallationSafe', Install Core Click run software (PUA)
30.00%

MicroWorld eScan
Gen:Variant.Adware.AdGazelle.1, Gen:Variant.Adware.Zusy.107390, Gen:Variant.Adware.Strictor.67719
28.00%

The domain downloads.installationsafe.net has been seen to resolve to the following 7 IP addresses.

ec2-54-235-78-83.compute-1.amazonaws.com
July 3, 2014

ec2-50-19-82-247.compute-1.amazonaws.com
July 3, 2014

ec2-54-235-184-148.compute-1.amazonaws.com
June 26, 2014

ec2-54-225-160-38.compute-1.amazonaws.com
June 9, 2014

ec2-54-83-16-155.compute-1.amazonaws.com
May 23, 2014

ec2-184-73-217-148.compute-1.amazonaws.com
May 1, 2014

ec2-23-23-99-57.compute-1.amazonaws.com
December 18, 2013

File downloads found at URLs served by downloads.installationsafe.net.

 
Latest 30 of 158 download URLs

Remove Malware from downloads.installationsafe.net - Powered by Reason Core Security