dl2.iq9download.com

InstallX, LLC

Domain Information

The domain dl2.iq9download.com registered by NATIVEX, LLC was initially registered in April of 2012 through ENOM, INC.. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Limelight Networks, Inc. network. The domain is associated with the publisher InstallX, LLC who is located in Sartell, Minnesota in the United States.
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Monday, April 16, 2012

Expires date:
Saturday, April 16, 2016

Updated date:
Thursday, December 10, 2015

ASN:
AS22822 LLNW-AS Limelight Networks, INC. proxy AS object

Root domain:

Scanner detections:
Detections  (90% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.InstallIQ, PUP.PlayPickle
90.00%

Trend Micro House Call
TROJ_GEN.F47V1128, TROJ_GEN.F47V0815, TROJ_GEN.F47V1024, TROJ_GEN.F47V1102, TROJ_GEN.F47V1111, TROJ_GEN.F47V1016, TROJ_GEN.F47V0926
90.00%

Sophos
InstallQ
90.00%

Comodo Security
Application.Win32.InstallIQ.B
90.00%

Dr.Web
Adware.W3i.32
90.00%

VIPRE Antivirus
InstallIQ Installer
90.00%

Avira AntiVirus
APPL/InstallIQ.Gen5, Adware/InstallIQ.N
90.00%

ESET NOD32
Win32/InstallIQ (variant)
90.00%

Reason Heuristics
PUP.Installer.InstallX.J, PUP.Installer.InstallX.T, PUP.Installer.InstallX.q, PUP.Installer.InstallX.Q, PUP.Installer.InstallX.R, PUP.InstallX.Installer (M)
90.00%

Bkav FE
W32.Clod53c.Trojan, W32.Clodac9.Trojan, W32.Clod405.Trojan, W32.Clod1fe.Trojan, W32.Clod4fe.Trojan, W32.Clodf6a.Trojan, W32.Clodfdb.Trojan
80.00%

K7 AntiVirus
Unwanted-Program , Riskware
80.00%

McAfee
Artemis!553CD710BF51, Artemis!A34F9AC02DB1, Artemis!55D1D28B91D9, Artemis!08C259690876, Artemis!AA0B88322D9D, Artemis!FE674CB1C169
80.00%

IKARUS anti.virus
AdWare.InstallIQ, Win32.SuspectCrc
70.00%

herdProtect (fuzzy)
a variant of f3daed5ebc041cc2e2f4153e44895e17d218e7ab, a variant of 3fbc6de9f1334f53143aea533acb7da976cc53a2, a variant of e7324fdf72fa6976b8d17215cef5ceeb292a3cb5
60.00%

Rising Antivirus
PE:PUF.InstallIQ!1.9E4F
60.00%

The domain dl2.iq9download.com has been seen to resolve to the following 5 IP addresses.

May 3, 2015

cdn-208-111-160-6.iad.llnw.net
September 3, 2014

cdn-208-111-161-254.iad.llnw.net
September 3, 2014

February 5, 2014

February 5, 2014

File downloads found at URLs served by dl2.iq9download.com.

16 / 68    (Adware)
http://dl2.iq9download.com/lm/.../fbdownloader.exe  (bb25ea23db409d0a821f091beb71edbc)

24 / 68    (Adware)

12 / 68    (Adware)

20 / 68    (Adware)
http://dl2.iq9download.com/lm/.../7zip_bimo.exe  (0b707c30b2dc59c2ac3751e46c77ec00)

24 / 68    (Adware)
http://dl2.iq9download.com/lm/.../coretemp_1236.exe  (d8570961730fb9c2ab3645401aae3a1d)

20 / 68    (Adware)

24 / 68    (Adware)

13 / 68    (Adware)

13 / 68    (Adware)

12 / 68    (Adware)
http://dl2.iq9download.com/lm/.../coretemp_1236.exe  (coretemp_1236(vérifier températur du processeur).exe)

26 / 68    (Adware)

2 / 68      (false positives)

The following 150 files have been seen to comunicate with dl2.iq9download.com in live environments.

 
Latest 20 of 292 files

URL:
http://dl2.iq9download.com/

Google Analytics:
UA-2249740

Title:
“Iq9download.com”

Description:
“Find Cash Advance, Debt Consolidation and more at Iq9download.com. Get the best of Insurance or Free Credit Report, browse our section on Cell Phones or learn about Life Insurance. Iq9download.com is the site for Cash Advance.”

Web server:
Microsoft-IIS/8.5 (ASP.NET) (Version: 4.0.30319)

30 of 692 related domains