vinstaller.com

NATIVEX, LLC

Domain Information

The domain vinstaller.com registered by NATIVEX, LLC was initially registered in May of 2013 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
ENOM, INC.

Server location:
Oregon, United States (US)

Create date:
Wednesday, May 22, 2013

Expires date:
Sunday, May 22, 2016

Updated date:
Thursday, December 10, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.InstallX.L, PUP.Installer.InstallX.O, PUP.Installer.InstallX.P, PUP.InstallX.Installer (M), PUP.InstallX (M)
100.00%

McAfee
Artemis!770086FD015A, Artemis!55A23E51D1FA, Artemis!40CE7E608BE6
36.36%

ESET NOD32
Win32/InstallIQ (variant)
36.36%

Trend Micro House Call
TROJ_GEN.R02KH0AHU13, TROJ_GEN.F47V0813, TROJ_GEN.F47V0818
36.36%

Sophos
InstallQ
36.36%

VIPRE Antivirus
InstallIQ Installer
36.36%

McAfee Web Gateway
Artemis!770086FD015A, Artemis!55A23E51D1FA, Artemis!40CE7E608BE6
36.36%

Malwarebytes
PUP.Optional.InstallIQ, PUP.Optional.InstallIQ.A
36.36%

K7 AntiVirus
Unwanted-Program , Riskware
27.27%

K7 Gateway Antivirus
Unwanted-Program , Riskware
27.27%

IKARUS anti.virus
Win32.SuspectCrc, AdWare.InstallIQ
27.27%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
18.18%

Comodo Security
Application.Win32.InstallIQ.B
18.18%

Dr.Web
Adware.Downware.1426
18.18%

Boost by Reason
Adware.Installer.InstallX.L
9.09%

The domain vinstaller.com has been seen to resolve to the following 4 IP addresses.

ec2-54-200-231-235.us-west-2.compute.amazonaws.com
December 23, 2015

ec2-52-24-226-194.us-west-2.compute.amazonaws.com
December 23, 2015

May 3, 2015

May 30, 2014

File downloads found at URLs served by vinstaller.com.

The following file have been seen to comunicate with vinstaller.com in live environments.

URL:
http://vinstaller.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
Microsoft-IIS/8.5 (ASP.NET)