gosecureinstall.com

Whois Privacy Corp.

Domain Information

The domain gosecureinstall.com registered by Whois Privacy Corp. was initially registered in March of 2014 through INTERNET.BS CORP.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network.
Registrar:
INTERNET DOMAIN SERVICE BS CORP

Server location:
Dublin City, Ireland (IE)

Create date:
Friday, March 21, 2014

Expires date:
Tuesday, March 21, 2017

Updated date:
Tuesday, March 22, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.SETUPDOTEXE.F, PUP.Adknowledge.SETUPDOTEXE.Bundler (M), PUP.Adknowledge.SETUPDOT.Bundler (M), PUP.Adknowledge.WARPINST.Bundler (M), PUP.Adknowledge (M)
100.00%

Malwarebytes
PUP.Optional.OptimumInstaller.A
41.18%

NANO AntiVirus
Trojan.Win32.IBryte.cvsxum, Trojan.Win32.IBryte.cwtffl, Trojan.Win32.Agent.cvofrk, Trojan.Win32.Downware.cvgamb
41.18%

Kaspersky
not-a-virus:Downloader.Win32.Agent, HEUR:Trojan.Win32.Generic
41.18%

Comodo Security
TrojWare.Win32.IBryte.S, Application.Win32.IBryte.U
41.18%

Dr.Web
Trojan.Siggen6.12978, Adware.Downware.2505, Adware.Downware.2249, Trojan.Packed.28561
41.18%

VIPRE Antivirus
Optimum Installer, Threat.4778314, Trojan.Win32.Generic
41.18%

Avira AntiVirus
Adware/iBryte.A.7733, Adware/iBryte.bxjn, Adware/iBryte.qoemni, Adware/iBryte.qoemno
41.18%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, Downloader.Agent
41.18%

Rising Antivirus
PE:Malware.Agent!6.162B, PE:Malware.iBryte!6.14B5
41.18%

AVG
Skodna.Generic, Adware AdPlugin
41.18%

Panda Antivirus
Trj/Genetic.gen
41.18%

K7 AntiVirus
Unwanted-Program
41.18%

Sophos
iBryte Optimum Installer, PUA 'iBryte Optimum Installer'
41.18%

avast!
Win32:Adware-gen [Adw], Win32:Somoto-N [PUP]
41.18%

The domain gosecureinstall.com has been seen to resolve to the following 5 IP addresses.

ns1.ibspark.com
April 2, 2016

ec2-23-21-189-120.compute-1.amazonaws.com
July 14, 2014

ec2-54-243-244-249.compute-1.amazonaws.com
July 14, 2014

ec2-23-21-100-173.compute-1.amazonaws.com
April 30, 2014

ec2-50-17-234-52.compute-1.amazonaws.com
April 4, 2014

File downloads found at URLs served by gosecureinstall.com.

1 / 68      (Adware)
http://gosecureinstall.com/o/.../Groovestream.exe  (e9cd490a61128d13b81df3855e8dc91f)

1 / 68      (Adware)
http://gosecureinstall.com/o/.../Setup.exe  (b16ae114d6635eb9fb0ec50541bae0df)

1 / 68      (Adware)
http://gosecureinstall.com/o/.../Setup.exe  (77ceb3906cfabff32e2c971c8c2463b4)

1 / 68      (Adware)
http://gosecureinstall.com/o/.../Setup.exe  (36e0acf209e8d0e76431af98410393f9)

1 / 68      (Adware)
http://gosecureinstall.com/o/.../Skype_Setup.exe  (e340ee5096b43c040a9fb4faefc2465b)

1 / 68      (Adware)
http://gosecureinstall.com/o/.../Skype_Setup.exe  (0cf83ecef7c9a9190e1c06c8b86e9f60)

1 / 68      (Adware)
http://gosecureinstall.com/o/.../Setup.exe  (03038ff7138b5a4ab815c12e8421a944)

1 / 68      (Adware)
http://gosecureinstall.com/o/.../Skype_Setup.exe  (10b38f5147456e3703819f90e07e7bda)

1 / 68      (Adware)
http://gosecureinstall.com/o/.../Setup.exe  (282ce455be635d06cad8926114a1e38b)

1 / 68      (Adware)
http://gosecureinstall.com/o/.../Setup.exe  (4f7aebb02bffc049ed8c51c242450089)

32 / 68    (Adware)
http://gosecureinstall.com/o/.../Skype_Setup.exe  (c1131ce95629c8441da09b99ed397d6f)

32 / 68    (Adware)
http://gosecureinstall.com/o/.../Skype_Setup.exe  (09d566d28b47dc86c4c9913b08a6901b)

38 / 68    (Adware)
http://gosecureinstall.com/o/.../Setup.exe  (09b460da92c5b0eb2413ad8768c24a73)

38 / 68    (Adware)
http://gosecureinstall.com/o/.../Setup.exe  (5c2e66c7a7926ca07ad0124bb889a7cf)

38 / 68    (Adware)
http://gosecureinstall.com/o/.../Setup.exe  (aed83486d0a225210d60caccf188e130)

26 / 68    (Adware)
http://gosecureinstall.com/o/.../Setup.exe  (256ea9e91e53e2787f29b261c702796b)

19 / 68    (Adware)
http://gosecureinstall.com/o/.../Setup.exe  (320a06535fa0a8d106d7fb3ae5d7852d)

The following 142 files have been seen to comunicate with gosecureinstall.com in live environments.

 
Latest 20 of 154 files

September 14, 2016

URL:
http://gosecureinstall.com/

Title:
“gosecureinstall.com”

Web server:
nginx