secured.nmsgv.us

Admonetizer Inc

Domain Information

The domain secured.nmsgv.us registered by Admonetizer Inc was initially registered in April of 2015 through GoDaddy.com, Inc.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, INC.

Server location:
Arizona, United States (US)

Create date:
Monday, April 20, 2015

Expires date:
Tuesday, April 19, 2016

Updated date:
Monday, April 20, 2015

Root domain:

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.InstallMonetizer.A, PUP.Optional.SushiLeads.A, PUP.Optional.Clara.A, PUP.Optional.CheckOffer, PUP.Optional.WindeskWinsearch
73.47%

Avira AntiVirus
PUA/Vittalia.Gen, PUA/InstallMonetizer.Gen
69.39%

NANO AntiVirus
Riskware.Nsis.Downware.cvzsgq, Trojan.Nsis.Downloader.djhpgw, Riskware.Win32.InstallMonetizer.dymuwe
67.35%

SUPERAntiSpyware
Adware.InstallMonetizer/Variant
65.31%

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF, NS:PUF.SilenceInstaller!1.9DDF[F1], PE:Malware.Generic/QRS!1.9E2D[F1], NS:Adware.Agent!1.A387 [F]
44.90%

Dr.Web
Adware.Downware.918, Adware.Pasta.18, Adware.Iminent.66, Threat.Undefined, Adware.Downware.12607, Adware.Searcher.2851, Adware.Downware.12736
42.86%

Baidu Antivirus
Adware.Win32.InstallMonetizer, PUA.Win32.InstallMonetizer, Hacktool.NSIS.SilentInstall
38.78%

ESET NOD32
Win32/InstallMonetizer.AT, Win32/InstallMonetizer.BG potentially unwanted, Win32/InstallMonetizer.AW potentially unwanted
34.69%

AVG
AdInstaller, MultiBundle, Generic, Could be an adware MultiBundle
32.65%

Kaspersky
not-a-virus:Downloader.NSIS.Agent, not-a-virus:AdWare.NSIS.Agent, not-a-virus:Downloader.NSIS.SilentInstall
30.61%

Sophos
AppMonetizer Installer, AppMonetizer Installer (PUA), PUA 'AppMonetizer Installer' (of type Adware), Winsearch (PUA)
30.61%

ESET NOD32
Win32/InstallMonetizer.BG potentially unwanted application, Win32/InstallMonetizer.AW potentially unwanted application, Win32/InstallMonetizer.BJ potentially unwanted application
26.53%

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen, Win32/Virus.Downloader.0ad, QVM42.0.Malware.Gen, HEUR/QVM42.0.Malware.Gen
24.49%

VIPRE Antivirus
InstallMonetizer, Threat.4786532, Trojan.Win32.Generic, Threat.4150696
18.37%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A, SoftwareBundler:Win32/InstallMonetizer, Threat.Undefined
14.29%

The domain secured.nmsgv.us has been seen to resolve to the following IP address.

ip-50-63-202-43.ip.secureserver.net
May 16, 2016

File downloads found at URLs served by secured.nmsgv.us.

7 / 68      (PUP)

2 / 68      (false positives)

1 / 68      (PUP)

8 / 68      (PUP)

1 / 68      (Adware)
http://secured.nmsgv.us/.../H-Alarm-Setup.exe  (db1779fe65f06e3ea107d0189f23f1eb)

4 / 68      (PUP)
http://secured.nmsgv.us/UC_Web_softpedia_10623.exe  (6f5649ac0fe7fd04029d99fb57f8fa53)

1 / 68      (PUP)

1 / 68      (PUP)

4 / 68      (PUP)
http://secured.nmsgv.us/Mp3_Converter0313_7470.exe  (82b33fd549c738af4f83c9c62f8c100a)

7 / 68      (PUP)

14 / 68    (PUP)

5 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (inconclusive)

6 / 68      (PUP)

7 / 68      (PUP)

5 / 68      (PUP)
http://secured.nmsgv.us/.../Bobrowser.exe  (15b994ee45a834eefd31c4f72411def2)

The following 5 files have been seen to comunicate with secured.nmsgv.us in live environments.

30 of 38 related domains