wiseconvert.com

Name Management Group

Domain Information

The domain wiseconvert.com registered by Name Management Group was initially registered in January of 2012 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Chicago, Illinois within the United States which resides on the GigeNET network.
Registrar:
GODADDY.COM, LLC

Server location:
Illinois, United States (US)

Create date:
Saturday, January 28, 2012

Expires date:
Saturday, January 28, 2017

Updated date:
Wednesday, March 30, 2016

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Conduit.O, PUP.Installer.ClientConnect.F, PUP.4327.Conduit.O, PUP.4605.Conduit.O, PUP.Conduit.Installer, PUP.Conduit.49019.Bundler, PUP.Conduit.Bundler (M), PUP.Perion.Bundler.Conduit.Installer (M), PUP.Perion.Bundler.Conduit (M), Win32.Generic, PUP.Perion.Bundler (M)
100.00%

Dr.Web
Adware.Conduit.3, Adware.Conduit.87, Adware.BGuard.15, Threat.Undefined, Adware.Conduit.6, Adware.InstallCore.101, Adware.InstallCore.122
20.83%

VIPRE Antivirus
Threat.4786236, Conduit
18.75%

Malwarebytes
PUP.Optional.Conduit.A, PUP.Optional.ClientConnect
14.58%

Trend Micro House Call
TROJ_GEN.F47V0522, TROJ_GEN.F47V0529, Suspicious_GEN.F47V0624, Suspicious_GEN.F47V0722, TROJ_GEN.F47V1103, TROJ_GEN.F47V0910
12.50%

avast!
Win32:Adware-BRM [PUP], Win32:Adware-gen [Adw], Win32:Installer-I [PUP]
12.50%

AVG
Generic, Potentially harmful program Toolbar.Conduit
12.50%

McAfee
Artemis!1BC6B9E64145, Artemis!63AD372E1DDC, Artemis!C5BB48AE8A2E, Artemis!D2E5A7B3F531, Artemis!03AB4BA7799B
10.42%

McAfee Web Gateway
Artemis!1BC6B9E64145, Artemis!63AD372E1DDC, Artemis!C5BB48AE8A2E, Artemis!D2E5A7B3F531, Artemis!PUP
10.42%

Baidu Antivirus
Adware.Win32.Conduit, Trojan.Win32.ClientConnect
10.42%

Fortinet FortiGate
Riskware/Toolbar_Conduit, Riskware/ClientConnect
10.42%

ESET NOD32
Win32/Toolbar.Conduit.AE, Win32/ClientConnect (variant), Win32/OpenCandy
10.42%

ESET NOD32
Win32/Toolbar.Conduit.M potentially unwanted application, Win32/Toolbar.Conduit.AJ potentially unwanted application, Win32/InstallCore.BL potentially unwanted application
8.33%

NANO AntiVirus
Riskware.Win32.Conduit.czvfwi, Riskware.Win32.BGuard.csnycu, Trojan.Win32.ClientConnect.deinfe
6.25%

F-Prot
W32/InstallCore.R.gen
6.25%

The domain wiseconvert.com has been seen to resolve to the following 5 IP addresses.

ip-69.39.236.56.hosted.by.gigenet.com
June 2, 2016

April 4, 2016

March 30, 2016

ip-50-63-202-52.ip.secureserver.net
February 8, 2016

184.173.251.169-static.reverse.softlayer.com
December 27, 2013

File downloads found at URLs served by wiseconvert.com.

3 / 68      (PUP)

1 / 68      (Adware)
http://wiseconvert.com/.../download_ab2.php  (wiseconvert_tsv51eozv.exe)

1 / 68      (PUP)

13 / 68    (PUP)

5 / 68      (PUP)
http://wiseconvert.com/.../downloadme.php  (451249d5d60830604ccf1c3c11a1e1c0684d8dc95c4b57f11d196a6536be3403)

1 / 68      (PUP)

The following 418 files have been seen to comunicate with wiseconvert.com in live environments.

 
Latest 20 of 432 files

September 4, 2014

April 4, 2016

URL:
http://wiseconvert.com/

Title:
“wiseconvert.com”

Web server:
Apache