54.235.251.129

IP Address Information

Currently there are 27 domain names that utilize this address. The primary domain hosted by this IP is install2.optimum-installer.com along with 26 other domains which are known adware distribution web sites. The address and domain is leased to Optimum Installer.
Scanner detections:
Detections  (88% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.PremiumInstaller.F, PUP.Installer.OptimumInstaller.K, PUP.Installer.OptimumInstaller.F, PUP.Installer.INSTALLTHIS.F, PUP.Installer.FileMonarch.F, PUP.Installer.Adknowledge, PUP.Installer.Softpulse, PUP.Bundler.Outbrowse, PUP.Installer.Groovecom, PUP.Bundler.Adknowledge, Threat.Adknowledge.Bundler, PUP.Adknowledge.Bundler, PUP.Air Software.AirSoftware.Bundler (M), PUP.Adknowledge.OptimumInstaller.Installer (M), PUP.Adknowledge.PremiumInstaller.Installer (M), Threat.Win.Reputation.IMP
97.78%

K7 Gateway Antivirus
Backdoor , Adware , Unwanted-Program , Riskware
77.78%

Agnitum Outpost
Adware.Agent, PUA.Agent, Adware.iBryte, Trojan.Agent, Adware.Generic, Riskware.AdWare, Riskware.Agent, PUA.OutBrowse, Trojan.Buzus
77.78%

avast!
Win32:IBryte-AD [PUP], Win32:IBryte-U [PUP], Win32:IBryte-CY [PUP], Win32:Installer-J [PUP], Win32:Adware-gen [Adw], Win32:PUP-gen [PUP]
77.78%

Dr.Web
Adware.iBryte.3, Adware.Downware.461, Trojan.Packed.26508, Adware.Downware.1078, Adware.iBryte.483, Program.Unwanted.79
77.78%

Malwarebytes
PUP.Optional.IBryte, PUP.Bundle.Installer.OI, PUP.Optional.OptimumInstaller.A, PUP.Optional.Ibryte, PUP.Optional.OptimunInstaller
75.56%

Kaspersky
not-a-virus:AdWare.Win32.Agent, not-a-virus:AdWare.Win32.iBryte, not-a-virus:AdWare.Win32.SoftPulse, not-a-virus:AdWare.Win32.OutBrowse
75.56%

NANO AntiVirus
Riskware.Win32.Agent.csoeby, Riskware.Win32.IBryte.cspvvp, Trojan.Win32.Agent.cxjjsz, Riskware.Win32.Agent.csnrpm, Trojan.Win32.IBryte.ddwawl
75.56%

VIPRE Antivirus
Optimum Installer, iBryte, Threat.4778314, Threat.4150696, Threat.4783369, Threat.4733199, Iminent
75.56%

Sophos
iBryte Optimum Installer, iBryte Premium Installer, PUA 'iBryte Optimum Installer', PUA 'SoftPulse' (of type Adware), PUA 'OutBrowse Revenyou'
75.56%

The following domains resolved to the IP address 54.235.251.129.

File URLs download from 54.235.251.129.

31 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Malware)
http://install2.optimum-installer.com/o/.../Setup.exe  (e643289a68e4653a13053f4734fd4a93)

44 / 68    (Adware)

40 / 68    (Adware)
http://install2.optimum-installer.com/o/.../Setup.exe  (321d583b7fff6d7cf11419d61b498727)

1 / 68      (Adware)

0 / 68
http://install2.optimum-installer.com/o/.../Setup.exe  (5e6fe58f787c1251c4698f80784acfda)

1 / 68      (Adware)

34 / 68    (Adware)
http://install2.optimum-installer.com/o/.../GetTest.exe  (2355ea7e5bd65f3299879bbf912ee0b2)

34 / 68    (Adware)
http://install2.optimum-installer.com/o/.../instalar.exe  (ea6d542401b4ceed480d26c47ff174c9)

31 / 68    (Adware)
http://install2.optimum-installer.com/o/.../ZNES.exe  (84ffb409cab74d3ff3ab6539ac5a271a)

34 / 68    (Adware)

28 / 68    (Adware)

The geographical location of this IP address.

Country:
United States (US)

Region:
Virginia

City:
Ashburn

Coordinates:
39.0437, -77.4875

ARIN WHOIS:
ERROR 503: Unable to service request due to high volume.


Autonomous System Assignment
ASNumber:
14618

ASName:
AMAZON-AES - Amazon.com, Inc.

ASHandle:
AS14618

Remove Malware from 54.235.251.129 - Powered by Reason Core Security