www.4sinstalls.com

WIRED 2000 CORPORATION

Domain Information

The domain www.4sinstalls.com registered by WIRED 2000 CORPORATION was initially registered in May of 2014 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Marietta, Georgia within the United States which resides on the NationalNet, Inc. network.
Registrar:
ENOM, INC.

Server location:
Georgia, United States (US)

Create date:
Friday, May 23, 2014

Expires date:
Tuesday, May 23, 2017

Updated date:
Tuesday, October 27, 2015

ASN:
AS22384 NATIONALNET-1 - NationalNet, Inc.,US

Root domain:

Scanner detections:
Detections  (90% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/AdWare.Primawega application, Win32/WebDevAZ.C potentially unwanted application, Win32/DownloadAdmin.Q potentially unwanted application
48.00%

Reason Heuristics
PUP.Installer.CashBuyerMedia, Threat.Win.Reputation.IMP, PUP.TomorrowSoftware.UprightMedia.Installer (M), PUP.TomorrowSoftware.SpiralMedia.Bundler (M), PUP.Fintech.Installer (M), PUP.DownloadAdmin.SafeInstallSoftware.Installer (M), PUP.Vittalia.CashBuyerMedia.Bundler (M), PUP.DownloadAdmin.RedLightMedia.Installer (M), PUP.RazorEdge.Bundler.Installer.Meta (M), PUP.Vittalia.CashBuye.Bundler (M)
44.00%

NANO AntiVirus
Trojan.Win32.XPACK.dprfbr, Trojan.Win32.DownloAdmin.dxgjmo, Trojan.Nsis.Startpage.dsmxsq, Riskware.Nsis.Downloader.dvsumk
40.00%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696
36.00%

AVG
Generic, Could be an adware AdInject
34.00%

ESET NOD32
Win32/DownloadAdmin.I potentially unwanted (variant), Win32/DownloadAdmin.N potentially unwanted (variant), Win32/AdWare.Primawega
32.00%

Vba32 AntiVirus
Downloader.Agent, SScope.Downware.DownloadAdmin, AdWare.Agent, suspected of Trojan.Downloader.gen.h
32.00%

Kaspersky
not-a-virus:Downloader.Win32.DownloAdmin, Trojan.Win32.Startpage
32.00%

Qihoo 360 Security
HEUR/QVM11.1.Malware.Gen, QVM42.0.Malware.Gen, HEUR/QVM42.0.Malware.Gen, HEUR/QVM42.1.Malware.Gen, HEUR/QVM10.1.Malware.Gen
28.00%

Baidu Antivirus
PUA.Win32.DownloadAdmin, PUA.Win32.WebDevAZ, Trojan.Win32.Startpage, Adware.Win32.Primawega
24.00%

K7 AntiVirus
Unwanted-Program , Adware
22.00%

SUPERAntiSpyware
Adware.Primawega/Variant
20.00%

Fortinet FortiGate
Riskware/DownloadAdmin, PossibleThreat.P0, PossibleThreat.P1
14.00%

McAfee
Artemis!2ABA762523B3, DownloadAdmin, Artemis!63F4F515A8DD, Trojan.Artemis!8E3A0E838C4F, Artemis!29475D1A3505, Artemis!AFC586409299
12.00%

IKARUS anti.virus
PUA.DownloadAdmin, not-a-virus:Downloader.Win32.SwiftCleaner
12.00%

The domain www.4sinstalls.com has been seen to resolve to the following IP address.

January 5, 2016

File downloads found at URLs served by www.4sinstalls.com.

21 / 68    (Adware)
http://www.4sinstalls.com/.../netdownloader.exe  (2aba762523b35710745a04cad6941eb1)

2 / 68      (inconclusive)
http://www.4sinstalls.com/.../BISetup.exe  (8f3133b24918e6799639e1bd80cdce1e)

21 / 68    (PUP)
http://www.4sinstalls.com/.../SearchLatina.exe  (afc58640929927b9c9a6517641ab38e8)

2 / 68      (PUP)
http://www.4sinstalls.com/.../IMSetup.exe  (3cd7a263a6d334efdf98380afae041f1)

URL:
http://www.4sinstalls.com/

Title:
“Free Chat Rooms Online”

Web server:
Apache/2.2.22 (Debian)