install.browsersafeguard.com

Optimum Installer

Domain Information

The domain install.browsersafeguard.com registered by Adknowledge was initially registered in May of 2013 through TUCOWS DOMAINS INC.. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform. The domain is associated with the publisher Optimum Installer who is located in Kansas City, Missouri in the United States.
Registrar:
TUCOWS DOMAINS INC.

Server location:
Virginia, United States (US)

Create date:
Monday, May 20, 2013

Expires date:
Friday, May 20, 2016

Updated date:
Friday, August 07, 2015

Scanner detections:
Detections  (82% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Adknowledge.U, PUP.BrowserSafeguard.Task.Z, PUP.Adknowledge.T, PUP.BrowserSafeguard.Z, PUP.Adknowledge.R
73.33%

Trend Micro House Call
TROJ_GEN.R0CBH08JI13, TROJ_GEN.R0C1H08LB13, TROJ_GEN.R047H08LG13, TROJ_GEN.R0CCH06K713, TROJ_GEN.F47V1102, TROJ_GEN.R02KH06K813
40.00%

McAfee Web Gateway
Adware-Bsafeg!340DE8E4F50A, Adware-Bsafeg!B95253CB9218, Adware-Bsafeg!FA4264FE10DE, Adware-Bsafeg!24F2E14EEFF0, Adware-Bsafeg!5244330DC68C
33.33%

G Data
Win32.Trojan.Agent.UIKNCT, Adware.Generic.657222, Trojan.GenericKD.1509813, Win32.Application.BrowserSafeGuard
26.67%

McAfee
Adware-Bsafeg!340DE8E4F50A, Adware-Bsafeg!B95253CB9218, Adware-Bsafeg!FA4264FE10DE, Adware-Bsafeg!24F2E14EEFF0
26.67%

Bkav FE
W32.Clod2bc.Trojan, W32.Clod932.Trojan, W32.Clodee3.Trojan, W32.Clod12f.Trojan
26.67%

VIPRE Antivirus
Adware.Bsafeg, AdKnowledge
26.67%

AVG
Generic5
20.00%

Panda Antivirus
Suspicious file, Trj/OCJ.D
20.00%

Malwarebytes
PUP.Optional.BundleInstaller.A
13.33%

Sophos
Mal/MSIL-BA
13.33%

Dr.Web
Adware.Bho.4004, Adware.Downware.1747
13.33%

MicroWorld eScan
Adware.Generic.657222, Trojan.GenericKD.1509813
13.33%

Bitdefender
Adware.Generic.657222, Trojan.GenericKD.1509813
13.33%

Lavasoft Ad-Aware
Adware.Generic.657222, Trojan.GenericKD.1509813
13.33%

The domain install.browsersafeguard.com has been seen to resolve to the following 14 IP addresses.

ec2-54-235-142-167.compute-1.amazonaws.com
May 18, 2016

ec2-23-21-193-65.compute-1.amazonaws.com
May 18, 2016

ec2-23-23-161-89.compute-1.amazonaws.com
April 14, 2016

ec2-23-23-172-222.compute-1.amazonaws.com
April 14, 2016

ec2-50-19-123-178.compute-1.amazonaws.com
March 30, 2016

ec2-23-23-147-166.compute-1.amazonaws.com
March 30, 2016

ec2-50-19-109-27.compute-1.amazonaws.com
February 20, 2016

ec2-50-19-244-255.compute-1.amazonaws.com
February 20, 2016

ec2-50-19-228-203.compute-1.amazonaws.com
February 8, 2016

ec2-50-17-190-156.compute-1.amazonaws.com
February 8, 2016

ec2-23-23-196-27.compute-1.amazonaws.com
January 3, 2016

ec2-23-21-252-205.compute-1.amazonaws.com
January 3, 2016

ec2-23-23-170-193.compute-1.amazonaws.com
September 4, 2014

ec2-54-243-76-114.compute-1.amazonaws.com
January 28, 2014

File downloads found at URLs served by install.browsersafeguard.com.

8 / 68      (PUP)
http://install.browsersafeguard.com/.../installer.exe  (b95253cb9218f42147407b7e6cfea406)

1 / 68      (Adware)
http://install.browsersafeguard.com/.../installer.exe  (uninstall.browsersafeguard.exe)

2 / 68      (Adware)
http://install.browsersafeguard.com/.../installer.exe  (uninstall.browsersafeguard.exe)

4 / 68      (Adware)
http://install.browsersafeguard.com/.../installer.exe  (uninstall.browsersafeguard.exe)

6 / 68      (PUP)

14 / 68    (Adware)

4 / 68      (Adware)

2 / 68      (Adware)
http://install.browsersafeguard.com/.../installer.exe  (uninstall.browsersafeguard.exe)

1 / 68      (Adware)

6 / 68      (Adware)
http://install.browsersafeguard.com/.../installer.exe  (uninstall.browsersafeguard.exe)

2 / 68      (Adware)

6 / 68      (Adware)
http://install.browsersafeguard.com/.../installer.exe  (uninstall.browsersafeguard.exe)

2 / 68      (Adware)

2 / 68      (inconclusive)
http://install.browsersafeguard.com/.../installer-dl.exe  (f7466ade639811080e203112993c6910)

8 / 68      (PUP)
http://install.browsersafeguard.com/.../installer-dl.exe  (44fce82153a8910d7b5994dd615f010d)

URL:
http://install.browsersafeguard.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)