The domain trk.airinstaller.com is registered by proxy through ENOM, INC. and was originally registered in May of 2011. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Digital Ocean, Inc. network. The domain is associated with the publisher Air Software who is located in Victoria, British Columbia in Canada.
New York, United States (US)
Thursday, May 12, 2011
Thursday, May 12, 2016
Saturday, May 02, 2015
AS14061 DIGITALOCEAN-ASN - Digital Ocean, Inc.
Detections (96% detected)
PUP.Installer.DownloadManager.F, PUP.Installer.TuguuSLU.F, DownloadManager.AirSoftware.M, DownloadManager.AirSoftware.K, DownloadManager.AirSoftware.F, DownloadManager.Bundler.Air Software, PUP.Air Software.AirSoftware.Bundler (M), PUP.Solimba.Bechiro.Bundler (M)
Unwanted-Program , Trojan , Adware
K7 Gateway Antivirus
Trojan.SMSSend.4902, Trojan.PayInt.14, Trojan.SMSSend.4684, Adware.Downware.1410, Adware.Downware.1167, Adware.Downware.963
Iminent, DomaIQ, AirInstaller, Threat.4782985, DownloadMR
ADWARE/Adware.Gen, APPL/DomaIQ.G.2, ADWARE/Adware.Gen7, Adware/AirInst.2556, APPL/Solimba.Gen, TR/Zusy.bmjkonyb
PE:PUF.Airinstall!1.9C4C, PE:PUF.DomaIQ!1.9EEB, PE:PUF.FirseriaInstaller@CV!1.5C42
BundleApp_r.D, Skodna.Generic_r, Adware Generic_r.JA, Adware Generic_r.IW, Adware InstallCore.RT, Adware InstallCore.RV
Application.Win32.DomaIQ.D, Application.Win32.AirAdInstaller.B, Application.Win32.AirAdInstaller.A, Application.Win32.Solimba.L
DomainIQ pay-per install, AirInstaller, PUA 'AirInstaller', Solimba Installer, PUA.AirInstaller
AdWare.MSIL.DomaIQ, AdWare.AirAdInstaller, TScope.Trojan.MSIL
AdWare.DomaIQ, Win32.AdWare, AdWare.Airinstall, PUA.AirAdInstaller, Win32.Malware, PUA.Bechiro
Win32:Malware-gen, Win32:DomaIQ-BB [PUP], Adware-gen [Adw], PUP-gen [PUP], Win32:Adware-CAH [PUP], Win32:Adware-gen [Adw]
W32/DomaIQ.B.gen, W32/AirInstall.C.gen, W32/AirInstall.A.gen, W32/AirInstall.D.gen, W32/AirInstall.A8.gen
Trojan.Win32.PayInt.csffwn, Riskware.Win32.AirAdInstaller.cwbltv, Riskware.Win32.Downware.cwfgel, Riskware.Win32.AirAdInstaller.cxhlas
The domain trk.airinstaller.com has been seen to resolve to the following 7 IP addresses.
May 3, 2015
May 3, 2015
September 5, 2014
May 31, 2014
May 7, 2014
May 1, 2014
April 13, 2014
File downloads found at URLs served by trk.airinstaller.com.
The following file have been seen to comunicate with trk.airinstaller.com in live environments.
“Air Installer ™”
Apache/2.2.22 (Ubuntu) (PHP/5.4.31-1+deb.sury.org~precise+1)