installl.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain installl.com is registered by proxy through GODADDY.COM, LLC and was originally registered in June of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Friday, June 29, 2012

Expires date:
Wednesday, June 29, 2016

Updated date:
Tuesday, June 30, 2015

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Conduit.V, PUP.4323.Conduit.S, PUP.ClientConnect.AA, PUP.4601.Conduit.S, PUP.Conduit.AA, PUP.Conduit.Installer, PUP.43015.Conduit.S, PUP.4604.Conduit, PUP.Conduit.4713.Bundler, PUP.Conduit.Bundler (M), PUP.Perion.Bundler.Conduit (M), PUP.Perion.Bundler (M)
91.84%

VIPRE Antivirus
Conduit, Threat.4786236
63.27%

Dr.Web
Adware.BGuard.15, Adware.Conduit.27, Adware.Conduit.87, Program.BrotherSoft.17, infected with BackDoor.Gbot.2729, Adware.Conduit.278
61.22%

Malwarebytes
PUP.Optional.Conduit.A, PUP.Optional.ClientConnect
48.98%

ESET NOD32
Win32/OpenCandy, Win32/Wajam (variant), Win32/Toolbar.Conduit.AE, Win32/Toolbar.Conduit.AE (variant), Win32/ClientConnect (variant)
46.94%

AVG
Generic, Potentially harmful program Toolbar.Conduit
40.82%

Trend Micro House Call
TROJ_GEN.F47V1113, TROJ_GEN.F47V0618, TROJ_GEN.F47V0331, TROJ_GEN.F47V0609, Suspicious_GEN.F47V0615, TROJ_GEN.F47V0519, Suspicious_GEN.F47V0611, Suspicious_GEN.F47V0621
38.78%

Fortinet FortiGate
Riskware/Wajam, Riskware/Toolbar_Conduit, Riskware/Conduit_SearchProtect
34.69%

avast!
Win32:Adware-BRM [PUP], Win32:Adware-gen [Adw]
34.69%

Baidu Antivirus
Adware.Win32.Conduit, PUA.Win32.ClientConnect, Trojan.Win32.ClientConnect
34.69%

McAfee
Artemis!D2D898250CDC, Artemis!C6BB2B9CAEE2, Artemis!518640C3E4C0, Artemis!7632B224E899, Artemis!F06373AC382F, Artemis!B572FA7DA772, Artemis!F9298F49350B, Artemis!5DE3F1B0209C, Artemis!19DE92BCBDA8, Artemis!5F17EFEF1044
28.57%

McAfee Web Gateway
Artemis!D2D898250CDC, Artemis!C6BB2B9CAEE2, Artemis!518640C3E4C0, Artemis!7632B224E899, Artemis!F06373AC382F, Artemis!B572FA7DA772
28.57%

Kaspersky
not-a-virus:WebToolbar.Win32.Agent, not-a-virus:WebToolbar.JS.Condonit
20.41%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud), Win32.HeurC.KVM099.a.(kcloud), VIRUS_UNKNOWN
16.33%

G Data
Win32.Application.ConduitBrothersoftTB, Gen:Variant.Adware.Strictor.63486, Win32.Adware.Conduit
16.33%

The domain installl.com has been seen to resolve to the following 4 IP addresses.

September 1, 2016

ip-184-168-221-50.ip.secureserver.net
July 14, 2016

66.228.121.140-static.reverse.softlayer.com
June 30, 2015

184.172.162.249-static.reverse.softlayer.com
July 28, 2013

File downloads found at URLs served by installl.com.

1 / 68      (Adware)
http://installl.com/.../download_sp.php  (installconverter_tsv49ytay.exe)

1 / 68      (PUP)
http://installl.com/.../download.php  (installl_converter.exe)

The following 794 files have been seen to comunicate with installl.com in live environments.

 
Latest 20 of 796 files

URL:
http://installl.com/

Title:
“Download Now”

Web server:
nginx/1.5.0 (PHP/5.3.29)

Facebook:
Shares:  2

Statistics above are for the previous month of November 2017.

30 of 32 related domains