96.45.82.197

http-redirection-d1.dnsmadeeasy.com

IP Address Information

The Internet Service Provider (ISP) that owns the network address of 96.45.82.197 is Tiggee LLC and located in Virginia within the United States. The IP Address resolves to the DNS record of http-redirection-d1.dnsmadeeasy.com. Currently there are 47 domain names that utilize this address. The primary domain hosted by this IP is www.bit89.com along with 46 other domains which are known adware distribution web sites.
Scanner detections:
Detections  (58% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Performersoft.R, PUP.Installer.PurpleTechSoftware.U, PUP.Installer.Performersoft.T, PUP.Installer.Performersoft.J, PUP.Installer.PerformerSoft.X, PUP.Softpulse.PluginUpdate.Bundler (M), PUP.Performersoft.InstallB.Installer (M)
60.87%

Dr.Web
Adware.Plugin.115, Adware.Downware.1295, Adware.Searcher.755, Adware.Searcher.73, Adware.Zugo.49, DLOADER.Trojan
56.52%

ESET NOD32
Win32/InstallBrain (variant), Win32/Toolbar.Besttoolbars, Win32/InstallBrain.AC (variant), Win32/InstallBrain.AJ (variant), Win32/Toolbar.Zugo
47.83%

Malwarebytes
Adware.InstallBrain, PUP.Optional.SpeedAnalysis.A, PUP.Zugo, PUP.Optional.PerformerSoft.A, PUP.Adware.Agent
34.78%

Trend Micro House Call
TROJ_SPNR.14FD13, TROJ_GEN.F47V0801, TROJ_GEN.F47V1122, TROJ_GEN.F47V0719, TROJ_GEN.RCBH2B7, TROJ_SPNV.03A114, TROJ_GEN.RCBB1AF
34.78%

Comodo Security
ApplicUnwnt.Win32.AdWare.IBrain.B, Heur.Suspicious, Application.Win32.InstallBrain.AF, UnclassifiedMalware
34.78%

McAfee Web Gateway
Artemis!C73979282F0B, Artemis!AD4D2FA45050, RDN/Generic PUP.x!bpg, Artemis!8AC02716631A, Artemis!352C4D49BE77, Artemis!9A04FA3A7270
34.78%

Sophos
InstallBrain, Generic PUA DN, Mal/Generic-S, BProtector
30.43%

Avira AntiVirus
APPL/InstallBrain.Gen5, Adware/InstallBrain.CE, APPL/InstallBrain.JU, TR/BProtector.Gen, Adware/Searchbar.a.87
30.43%

Kingsoft AntiVirus
Win32.HeurC.KVM019.a.(kcloud), Win32.Troj.BrainInst.t.(kcloud), Win32.Troj.Generic.a.(kcloud), VIRUS_UNKNOWN, Win32.Troj.Generic.(kcloud)
30.43%

The following domains resolved to the IP address 96.45.82.197.

File URLs download from 96.45.82.197.

1 / 68      (PUP)

1 / 68      (Adware)

27 / 68    (PUP)
http://www.bit89.com/download/.../PcPerformer_SetupT.exe  (e2688bf523ea994b674509c17d517757)

1 / 68      (Adware)

1 / 68
http://vuze.com/vuze-leap/download/.../VuzeLeapSetup.exe  (6191ba2d703df190053685148937ec80)

1 / 68
http://vuze.com/vuze-leap/download/.../VuzeLeapSetup.exe  (4e75de5ee5e0a5b2885b10b226c74378)

1 / 68
http://vuze.com/leap-beta/.../VuzeLeapSetup.exe  (a11994c445b6c0bbb40bc61f54bc43a7)

1 / 68
http://vuze.com/leap-beta/.../VuzeLeapSetup.exe  (735e19dee7f5f167be0f12b9afad3b1a)

1 / 68
http://vuze.com/vuze-leap/download/.../VuzeLeapSetup.exe  (0b3e687ba38022638f01503f2a0395e2)

11 / 68    (Adware)

1 / 68
http://vuze.com/leap-beta/.../VuzeLeapSetup.exe  (84582d8335706923491739e710b657b0)

3 / 68      (inconclusive)
http://performersoft.com/.../DriverPerformerSetup2.exe  (bbd656fa45ca147232a0004a6e1589b6)

7 / 68      (Adware)
http://performersoft.com/.../pcperformer.exe  (43d37c256be8f2fca2d8e9140d1f7d5d)

0 / 68

25 / 68    (Adware)
http://www.bit89.com/uninstaller.exe  (9a04fa3a72706559493a61a804806801)

4 / 68      (Adware)
http://performersoft.com/drivers/.../Drivers.exe  (824a5f98d60619774973b9762a5aec9d)

1 / 68
http://bit89.com/download/.../TVNoop_Lite_Setup_1.exe  (9b195d6413ab1ac2ca1fd93e499fe4c1)

9 / 68      (Adware)
http://www.bit89.com/download/.../ibdp.exe  (fa5a9e9af5f677b0fd675442439fa1e4)

21 / 68    (PUP)

50 / 68    (PUP)

18 / 68    (Adware)
http://softologic.com/files/.../SpeedAnalysisSetup04.exe  (ad4d2fa450502c28bf3650ba31ae4cd0)

32 / 68    (PUP)
http://www.bit89.com/download/.../PCperformer_Setup.exe  (c73979282f0b3e3b07475771e12f4ce6)

The following file have been seen to comunicate with this IP address in live environments.

The geographical location of this IP address.

Country:
United States (US)

Region:
Virginia

City:
Reston

Coordinates:
38.9389, -77.3462

The ARIN network assigned organization for IP address 96.45.82.197.

Org name:
Tiggee LLC

Org identifier:
TIGGE

Org country:
United States (US)

Org region:
Virginia

Org city:
Reston

Org address:
11490 Commerce Park Drive, Suite 140

Org website:
http://www.tiggee.com

ARIN WHOIS:
NetRange: 96.45.80.0 - 96.45.95.255
CIDR: 96.45.80.0/20
OriginAS: AS16552
NetName: TIGGEE-USNYC-1
NetHandle: NET-96-45-80-0-1
Parent: NET-96-0-0-0-0
NetType: Direct Allocation
Comment: http://www.tiggee.com
Comment: Please report all abuse to abuse@tiggee.net
RegDate: 2009-10-09
Updated: 2012-03-20
Ref: http://whois.arin.net/rest/net/NET-96-45-80-0-1

OrgName: Tiggee LLC
OrgId: TIGGE
Address: 11490 Commerce Park Drive, Suite 140
City: Reston
StateProv: VA
PostalCode: 20191
Country: US
RegDate: 2004-09-09
Updated: 2011-07-27
Ref: http://whois.arin.net/rest/org/TIGGE

OrgTechHandle: TECH140-ARIN
OrgTechName: Tech
OrgTechPhone: +1-703-935-1598
OrgTechEmail: tech@tiggee.com
OrgTechRef: http://whois.arin.net/rest/poc/TECH140-ARIN

OrgAbuseHandle: ABUSE699-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-703-935-1598
OrgAbuseEmail: abuse@tiggee.com
OrgAbuseRef: http://whois.arin.net/rest/poc/ABUSE699-ARIN

RTechHandle: TECH140-ARIN
RTechName: Tech
RTechPhone: +1-703-935-1598
RTechEmail: tech@tiggee.com
RTechRef: http://whois.arin.net/rest/poc/TECH140-ARIN

RAbuseHandle: ABUSE699-ARIN
RAbuseName: Abuse
RAbusePhone: +1-703-935-1598
RAbuseEmail: abuse@tiggee.com
RAbuseRef: http://whois.arin.net/rest/poc/ABUSE699-ARIN

RNOCHandle: NOC2652-ARIN
RNOCName: NOC
RNOCPhone: +1-703-935-1598
RNOCEmail: noc@tiggee.com
RNOCRef: http://whois.arin.net/rest/poc/NOC2652-ARIN


Autonomous System Assignment
ASNumber:
16552

ASName:
TIGGEE - Tiggee LLC

ASHandle:
AS16552

Remove Malware from 96.45.82.197 - Powered by Reason Core Security