install.multinstaller.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain install.multinstaller.com is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2011. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Zurich, Zurich within Switzerland which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Zurich, Switzerland (CH)

Create date:
Tuesday, October 25, 2011

Expires date:
Tuesday, October 25, 2016

Updated date:
Wednesday, August 13, 2014

ASN:
AS19905 NEUSTAR-AS6 - NeuStar, Inc.,US

Root domain:

Google Safe Browsing:
malware

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.AbleSearchSystems.L, PUP.AbleSearchSystems (M), PUP.AbleSearchSystems.Installer (M), PUP.Media Labs.MediaLabs (M), PUP.Media Labs.MediaLab.Installer (M), PUP.AbleSear (M), PUP.Media Labs.MediaLab (M)
90.00%

F-Prot
W32/MediaLabs.A.gen, W32/Multibar.A.gen, W32/Downloader.DR.gen
30.00%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
30.00%

avast!
Ivelog-D [PUP], Win32:PUP-gen [PUP], Win32:Ivelog-D [PUP]
30.00%

Kaspersky
not-a-virus:WebToolbar.Win32.MultiBarDownloader, not-a-virus:HEUR:WebToolbar.Win32.MultiBarDownloader
30.00%

NANO AntiVirus
Riskware.Win32.Webtoolbar.jjmtg, Riskware.Win32.WebToolbar.uvphe, Riskware.Win32.Bho.ddbnpl
30.00%

Agnitum Outpost
PUA.Toolbar.MultiBarDown, Riskware.Agent
30.00%

Sophos
Multbar, Generic PUA AG, Generic PUA EM (PUA)
30.00%

Comodo Security
TrojWare.Win32.Downloader.Agent.TTS, ApplicUnwnt.Win32.WebToolbar.MultiBarDownloader.io, TrojWare.Win32.Multibar.A
30.00%

G Data
Win32.Adware.Multibar, Trojan.Generic.7799753
30.00%

Vba32 AntiVirus
Downware.iDatix.gen, Downloader.LMN, WebToolbar.MultiBarDownloader
30.00%

Fortinet FortiGate
W32/MultiBarDownloader!tr, Riskware/Multibar.AA
30.00%

AVG
Potentially harmful program Toolbar.Multibar, Downloader
20.00%

Dr.Web
hacktool program Tool.InstallToolbar.64, Tool.InstallToolbar.46
20.00%

Malwarebytes
PUP.BundleInstaller.MB, PUP.Optional.ToolbarInstaller.MB
20.00%

The domain install.multinstaller.com has been seen to resolve to the following 3 IP addresses.

April 20, 2016

June 26, 2015

October 9, 2014

File downloads found at URLs served by install.multinstaller.com.

1 / 68      (PUP)

The following 7 files have been seen to comunicate with install.multinstaller.com in live environments.

URL:
http://install.multinstaller.com/

Title:
“multinstaller.com”

Web server:
Apache