secure.11-pn-installer.com

Adknowledge  (via a Proxy Registrant)

Domain Information

This is a distribution host for a number of Adknowledge installers including (Fusion Installer, Wrap Installer, Premium Instal, Optimum Installer and many others). The installers are bundled download managers that include adware/ad-supported offers. The domain secure.11-pn-installer.com is registered by proxy through TUCOWS DOMAINS INC. and was originally registered in April of 2014. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network. The domain is associated with the publisher Adknowledge.
Remove Malware from secure.11-pn-installer.com - Powered by Reason Core Security
Registrar:
TUCOWS DOMAINS INC.

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Tuesday, April 15, 2014

Expires date:
Friday, April 15, 2016

Updated date:
Tuesday, April 14, 2015

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Adknowledge.FusionInstall.Installer (M), PUP.Adknowledge.Fileangels.Bundler (M), PUP.Adknowledge.Fileprotected.Bundler (M), PUP.Adknowledge.SafeDown.Bundler (M), PUP.Softpulse.PLUGINUPDATE.Bundler (M), PUP.installCore.CompilerIdea.Installer (M), PUP.Adknowledge.Fileadventure.Bundler (M), PUP.Vittalia.InstallAssistant.Installer (M), PUP.TapGamez.TapGamez2013.Installer (M)
100.00%

VIPRE Antivirus
Threat.4150696, Threat.4778314, Threat.4798837, Threat.5065747
94.00%

avast!
Win32:IBryte-DB [PUP], Win32:Adware-gen [Adw], Win32:Rootkit-gen [Rtk], PUP-gen [PUP], Win32:IBryte-DI [PUP], Win32:PUP-gen [PUP]
94.00%

Comodo Security
Application.Win32.iBryte.WRP, Application.Win32.AgentCV.HWYE, Application.Win32.Ibryte.NW, Application.Win32.InstallCore.DJS
94.00%

G Data
Gen:Variant.Application.Bundler.OptimumInstaller, Win32.Adware.IBryte, Gen:Variant.Adware.Graftor.165252, Gen:Variant.Application.Graftor.152464
94.00%

AVG
Adware AdPlugin, Adware InstallCore, Generic6
94.00%

Dr.Web
Trojan.Packed.26807, Adware.iBryte.486, Trojan.iBryte.445, Adware.iBryte.493, Trojan.iBryte.507, Trojan.Packed.27691, Trojan.DownLoader11.34079
94.00%

K7 Gateway Antivirus
Unwanted-Program , Adware
94.00%

K7 AntiVirus
Unwanted-Program , Adware
94.00%

Avira AntiVirus
APPL/OptInstal.opwb, ADWARE/iBryte.Gen4, Adware/iBryte.bxpg, ADWARE/iBryte.Gen7, PUA/InstallCore.A.10, Adware/iBryte.bxov
94.00%

Vba32 AntiVirus
AdWare.iBryte, suspected of Trojan.Downloader.gen.h, Malware-Cryptor.InstallCore.gen, Downloader.Agent
94.00%

MicroWorld eScan
Gen:Variant.Application.Bundler.OptimumInstaller.1, Gen:Variant.Application.Graftor.152464, Gen:Variant.Adware.Graftor.165252
92.00%

Malwarebytes
PUP.Optional.OptimumInstaller.A, PUP.Optional.OptimunInstaller, PUP.Optional.iBryte, PUP.Optional.InstallCore.SID.C
92.00%

NANO AntiVirus
Trojan.Win32.Zusy.cyhpmk, Riskware.Win32.IBryte.desauy, Trojan.Win32.IBryte.djoxrs, Trojan.Win32.Badur.dhhunu, Riskware.Win32.Downware.dobdfn
92.00%

Kaspersky
not-a-virus:AdWare.Win32.iBryte, Trojan.Win32.Badur, Trojan.Win32.Buzus, not-a-virus:Downloader.Win32.Agent
92.00%

The domain secure.11-pn-installer.com has been seen to resolve to the following 7 IP addresses.

unallocated.barefruit.co.uk
May 2, 2015

ec2-54-243-186-169.compute-1.amazonaws.com
October 19, 2014

ec2-54-243-183-125.compute-1.amazonaws.com
October 19, 2014

ec2-107-20-176-238.compute-1.amazonaws.com
September 13, 2014

ec2-107-20-176-51.compute-1.amazonaws.com
September 13, 2014

ec2-54-197-244-146.compute-1.amazonaws.com
May 21, 2014

ec2-54-197-244-130.compute-1.amazonaws.com
May 21, 2014

File downloads found at URLs served by secure.11-pn-installer.com.

33 / 68    (Adware)
http://secure.11-pn-installer.com/o/.../setup.exe  (d5d32efec36d1d41a569aba32a8ad466)

42 / 68    (Adware)
http://secure.11-pn-installer.com/o/.../update.exe  (96b503397a1e6f9729af97d7144ed366)

39 / 68    (Adware)

33 / 68    (Adware)
http://secure.11-pn-installer.com/o/.../setup.exe  (b178d21239b0714eabde30b1e61c6454)

42 / 68    (Adware)
http://secure.11-pn-installer.com/o/.../java_setup.exe  (684a4fc6c8ad21405139d9850fd47f94)

33 / 68    (Adware)
http://secure.11-pn-installer.com/o/.../setup.exe  (c1d73db7b327d06a927978da07c9242c)

1 / 68      (Adware)
http://secure.11-pn-installer.com/o/.../install.exe  (514a5682a5cc86e8d12643e084e9f86b)

The following 142 files have been seen to comunicate with secure.11-pn-installer.com in live environments.

 
Latest 20 of 142 files

URL:
http://secure.11-pn-installer.com/

Web server:
nginx/1.0.15

30 of 33 related domains

Remove Malware from secure.11-pn-installer.com - Powered by Reason Core Security