ca.offers.multiinstall.com

New Ventures Services, Corp

Domain Information

The domain ca.offers.multiinstall.com registered by New Ventures Services, Corp was initially registered in May of 2016 through RALLY CRY DOMAINS, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Road Town, British Virgin Islands within VG which resides on the Confluence Networks Inc network.
Registrar:
RALLY CRY DOMAINS, LLC

Server location:
British Virgin Islands, VG (VG)

Create date:
Sunday, May 8, 2016

Expires date:
Monday, May 8, 2017

Updated date:
Sunday, May 15, 2016

ASN:
AS40034 CONFLUENCE-NETWORK-INC - Confluence Networks Inc,VG

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.UnilogicInformaticaaME.d, PUP.Installmatic.UnilogicInformaticaaME.Installer (M), PUP.Installmatic.Unilogic.Installer (M)
100.00%

avast!
Win32:Downloader-TQT [PUP]
33.33%

AVG
MalSign.Generic
33.33%

The domain ca.offers.multiinstall.com has been seen to resolve to the following IP address.

May 16, 2016

File downloads found at URLs served by ca.offers.multiinstall.com.

3 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

The following 2 files have been seen to comunicate with ca.offers.multiinstall.com in live environments.

URL:
http://ca.offers.multiinstall.com/

Web server:
Apache