i1.stylezip.info

WEB PICK - INTERNET HOLDINGS LTD

Domain Information

stylezip.info is a landing page for the download and installtion of software wrapped with the WebPick Internet Holdings InstalleRex download manager which distributes adware web browser extensions and utility offers in the installer. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Columbus, Ohio within the United States which resides on the Ecommerce Corporation network. The domain is associated with the publisher WEB PICK - INTERNET HOLDINGS LTD who is located in Ramat Hasharon, Israel.
Registrar:
GoDaddy.com, LLC

Server location:
Ohio, United States (US)

ASN:
AS32392 OPENTRANSFER-ECOMMERCE - Ecommerce Corporation,US

Root domain:

Scanner detections:
Detections  (88% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.WhiteSmoke.V, PUP.KEYDOWNLOAD.Q, Unnamed.Threat.19, Unnamed.Threat.25, Unnamed.Threat.38, PUP.OptimizerPro.Task.M, PUP.Installer.SIENSA.H, PUP.Installer.GTCONSULTORIAEMINFORMATICAA.J, PUP.BanyanTreeTechnology (M), PUP.Optional.BeijingAmazGameAgeInternetTechnologyCo.Installer
82.05%

Bkav FE
W32.Clod256.Trojan, W32.Clod46e.Trojan, W32.Clod364.Trojan, W32.Clod005.Trojan, W32.Clod433.Trojan, W32.Clod89a.Trojan, W32.Cloddb2.Trojan, W32.Clodd3f.Trojan, W32.Clod54e.Trojan, W32.Clod5ca.Trojan, W32.Clod33f.Trojan, W32.XalunuC.Trojan, W32.Clod19d.Trojan, W32.Clodcb6.Trojan, W32.Clodf28.Trojan, W32.Clod6f7.Trojan, HW32.CDB, W32.Clod6fc.Trojan, W32.Clodd3a.Trojan, HW32.Stranacty
58.97%

Malwarebytes
PUP.Optional.Otshot.A, PUP.Optional.SProtect.A, PUP.Optional.MultiPlug.A, PUP.Optional.EZDownloader.A, PUP.Optional.BetterSoft.A, PUP.Optional.Aartemis.A, PUP.Optional.OptimizerPro.A
58.97%

Dr.Web
Adware.Downware.1400, Adware.Downware.1244, Adware.BGuard.11, Trojan.DownLoad3.29733, Trojan.DownLoad3.30962, Trojan.DownLoad3.30969
56.41%

VIPRE Antivirus
Adware.KeyDownload, Sprotector, Trojan.Win32.Generic, Trojan.Win32.Generic!SB.0, Iminent, Trojan.StartPage, Elex Installer
56.41%

McAfee
Artemis!38F61D046E57, Artemis!2041AF161372, RDN/Generic.grp!gg, RDN/Generic Downloader.x!ip, Artemis!1D283DD3AE23, Artemis!903C06F02D54, Artemis!48592EA4F119
53.85%

Trend Micro House Call
TROJ_GEN.R0CBH0AHR13, ADW_SPROTECT, TROJ_AGENTT.KOR, TROJ_DLOADR.MSA, ADW_EMOTICONS, TROJ_GEN.F47V0611, TROJ_SPNR.29L213, TROJ_GEN.F47V0904, TROJ_GEN.F47V1205, TROJ_APPINIT.BMH, TROJ_GEN.F47V1109
51.28%

ESET NOD32
Win32/Amonetize (variant), Win32/TrojanDownloader.Agent.AFD (variant), Win32/Duckegg, Win32/SProtector (variant), Win32/InstalleRex
46.15%

Comodo Security
Application.Win32.SProtect.GT, Application.Win32.Bundledz.C, TrojWare.Win32.Agent.~huf, UnclassifiedMalware, Heur.Suspicious
43.59%

Baidu Antivirus
Trojan.Win32.Agent, Trojan.Win32.Duckegg, Adware.Win32.BHO, Trojan.Win32.Downloader, Trojan.Win32.Toolbar, Adware.Win32.ELEX
41.03%

Sophos
Amonetize, Generic PUA BD, BProtector, Mal/Generic-S, BProtect BHO Plugin, Generic PUA AE, Troj/Bdoor-BFO, Generic PUA OA
38.46%

MicroWorld eScan
Adware.Agent.NRJ, Adware.Generic.545897, Gen:Variant.Symmi.14078, Gen:Variant.Adware.BHO.Bprotector.1, Adware.Generic.551876, ADSPY/AdSpy.Gen, Application.Downloader.SV
38.46%

AVG
Generic5, Downloader.Generic13, MultiDropper_c, Downloader.Agent2, Generic30, Generic_r, SHeur4, Dropper.Generic_r, MalSign.Generic
38.46%

avast!
Win32:WhiteSmoke-A [PUP], NSIS:SProtector-A [PUP], Win32:Agent-ASGX [Trj], Win32:Adware-AYT [PUP], Win32:Adware-BCA [Adw]
35.90%

G Data
Adware.Agent.NRJ, Adware.Generic.545897, Gen:Variant.Symmi.14078, Gen:Variant.Adware.BHO.Bprotector, Adware.Generic.551876
35.90%

The domain i1.stylezip.info has been seen to resolve to the following IP address.

February 2, 2016

File downloads found at URLs served by i1.stylezip.info.

0 / 68
http://i1.stylezip.info/.../agent2.exe  (fec4d31ff0db6b9ef5464a1ed8d72c5c)

8 / 68      (Adware)
http://i1.stylezip.info/.../setup__166.exe  (setup__2834_i45994058.exe)

6 / 68      (PUP)
http://i1.stylezip.info/.../whitesmoke_extract.exe  (e998dc852a2b1f7729364130e893d298)

8 / 68      (PUP)
http://i1.stylezip.info/addons/.../psupport_install.exe  (d8f98fcafae9392c875afe170c8ff803)

1 / 68      (Adware)

26 / 68    (PUP)

22 / 68    (PUP)

8 / 68      (PUP)

6 / 68      (Adware)
http://i1.stylezip.info/.../OtshotInstaller7.exe  (cdf9077311b6b364395baa22ad48c7d3)

1 / 68      (PUP)

1 / 68      (Adware)
http://i1.stylezip.info/.../wpc_ar_qvo6_1003.exe  (5d58b58a8011037f510da1f206fa0d88)

7 / 68      (Adware)
http://i1.stylezip.info/.../Bundle.exe  (ccdd204aee9d16e824e927aaee4ed575)

3 / 68      (inconclusive)

23 / 68    (PUP)

1 / 68      (Adware)
http://i1.stylezip.info/.../wpc_ar_201385172254_qvo6.exe  (a1011b0cc6834d4d5f1ba087694b4002)

4 / 68      (Adware)

16 / 68    (Adware)

32 / 68    (Adware)

13 / 68    (Adware)

11 / 68    (Adware)

8 / 68      (Adware)
http://i1.stylezip.info/.../sinstall.exe  (71c2ea2b936ba80f4bad80937b369adf)

19 / 68    (Adware)
http://i1.stylezip.info/addons/.../easylife_setup.exe  (cfc989b7c271653cafc96b624cabe194)

6 / 68      (PUP)
http://i1.stylezip.info/addons/.../optimizerpro.exe  (775109f391b83c13cf87a4c91a9866e3)

14 / 68    (PUP)
http://i1.stylezip.info/.../gadgetbox.exe  (e3cd117e62b1d06b19b7393ab152fdcd)

8 / 68      (Adware)
http://i1.stylezip.info/.../uninstaller.exe  (2041af161372f15b11295c48411ab2d2)

9 / 68      (Malware)

6 / 68      (Malware)

 
Latest 30 of 43 download URLs

URL:
http://i1.stylezip.info/

Title:
“jun”

Web server:
ASP.NET (ASP.NET) (ASP.NET) (ASP.NET)