go.darkcrack.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain go.darkcrack.com is registered by proxy through ENOM, INC. and was originally registered in March of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the Hostwinds LLC. network.
Registrar:
ENOM, INC.

Server location:
Texas, United States (US)

Create date:
Monday, March 5, 2012

Expires date:
Wednesday, March 5, 2014

Updated date:
Friday, October 18, 2013

ASN:
AS13354 ASN-EBLGLOBAL - EBL Global Networks, Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Bkav FE
W32.Clod009.Trojan
100.00%

McAfee
Artemis!E328593BCF74
100.00%

Malwarebytes
PUP.Optional.InstallIQ
100.00%

Sophos
InstallQ
100.00%

Comodo Security
Application.Win32.InstallIQ.B
100.00%

Dr.Web
Adware.W3i.32
100.00%

VIPRE Antivirus
InstallIQ Installer
100.00%

Avira AntiVirus
APPL/InstallIQ.Gen5
100.00%

ESET NOD32
Win32/InstallIQ (variant)
100.00%

IKARUS anti.virus
Win32.SuspectCrc
100.00%

AVG
Skodna.Generic_c
100.00%

Reason Heuristics
PUP.Installer.InstallX.T
100.00%

The domain go.darkcrack.com has been seen to resolve to the following IP address.

shared1.hostwindsdns.com
February 6, 2014

File downloads found at URLs served by go.darkcrack.com.

12 / 68    (Adware)
http://go.darkcrack.com/vioplayer  (vioplayer2_d3993213.exe)

12 / 68    (Adware)
http://go.darkcrack.com/.../  (vioplayer2_d3993213.exe)

The following file have been seen to comunicate with go.darkcrack.com in live environments.

URL:
http://go.darkcrack.com/

Title:
“ERS Admin”

Web server:
LiteSpeed (PHP/5.4.20)

Alexa:
Global rank:  4,804,328
Backlinks:  2

Statistics are for the previous month (Alexa statistics are for entire darkcrack.com).