installer.betterinstaller.com

Somoto Ltd.  (via a Proxy Registrant)

Domain Information

The domain installer.betterinstaller.com is registered by proxy through GODADDY.COM, LLC and was originally registered in May of 2011. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Steele, Nordrhein-Westfalen within Germany which resides on the RIPE Network Coordination Centre network. The domain is associated with the publisher Somoto Ltd. who is located in Tel Aviv, Israel.
Registrar:
GODADDY.COM, LLC

Server location:
Nordrhein-Westfalen, Germany (DE)

Create date:
Friday, May 27, 2011

Expires date:
Friday, May 27, 2016

Updated date:
Sunday, May 10, 2015

ASN:
AS25074 INETBONE-AS MESH GmbH

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.BetterInstaller.Somoto.BB, PUP.BetterInstaller.Somoto.R, PUP.Somoto.I, PUP.Somoto.BetterInstaller.Installer, PUP.Somoto.Bundler (M), PUP.Somoto.SomotoIs.Bundler (M)
100.00%

Clam AntiVirus
Adware.Somoto-1, Win.Adware.Somoto
68.75%

Sophos
Somoto BetterInstaller, PUA 'Somoto BetterInstaller'
68.75%

Dr.Web
Adware.Somoto.17, Adware.Somoto.8, Trojan.Packed.28357
68.75%

F-Prot
W32/SomotoBetterInstaller.A
62.50%

VIPRE Antivirus
BetterInstaller, Threat.4150696, Threat.4783461
62.50%

SUPERAntiSpyware
Adware.Somoto, Adware.Somoto/Variant, PUP.Somoto/Variant
62.50%

AVG
AdInstaller.Somoto, BTInternet.G, Generic, Adware AdInstaller.Somoto
62.50%

Malwarebytes
PUP.Optional.Somoto, PUP.Optional.Somoto.A
56.25%

K7 AntiVirus
Unwanted-Program , Trojan
56.25%

avast!
Win32:Somoto-F [PUP], Win32:PUP-gen [PUP]
56.25%

Comodo Security
Application.Win32.Somoto.A, Application.Win32.Somoto.CK
56.25%

Avira AntiVirus
Adware/BetterInstaller.QB, APPL/Somoto.itv.526, Adware/Instoolbar.A, APPL/Somoto.JBL, APPL/Somoto.Gen2, APPL/Somoto.ITG.48
56.25%

ESET NOD32
Win32/Somoto, Win32/Somoto (variant)
56.25%

NANO AntiVirus
Trojan.Win32.Agent.cruvhh, Riskware.Nsis.Adware.dbnhrj, Trojan.Win32.Somoto.csrqje, Riskware.Win32.Downware.digcac
43.75%

The domain installer.betterinstaller.com has been seen to resolve to the following IP address.

December 26, 2013

File downloads found at URLs served by installer.betterinstaller.com.

 
Latest 30 of 99 download URLs

URL:
http://installer.betterinstaller.com/

Web server:
nginx