dl2.iqdownload.com

REACTIVATION PERIOD

Domain Information

The domain dl2.iqdownload.com registered by REACTIVATION PERIOD was initially registered in March of 2011 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Limelight Networks, Inc. network.
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Thursday, March 17, 2011

Expires date:
Friday, March 17, 2017

Updated date:
Friday, March 18, 2016

ASN:
AS22822 LLNW-AS Limelight Networks, INC. proxy AS object

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.W3i.K, PUP.Installer.W3i.M, PUP.Installer.W3i.g, Threat.InstallX.Installer, PUP.InstallX.W3i.Installer (M)
100.00%

Avira AntiVirus
APPL/InstallIQ.Gen5
40.00%

ESET NOD32
Win32/InstallIQ (variant)
40.00%

Trend Micro House Call
TROJ_GEN.F47V1231, TROJ_GEN.R047H0AIR13, TROJ_GEN.F47V1219
30.00%

Dr.Web
Adware.W3i.32
30.00%

VIPRE Antivirus
InstallIQ Installer
30.00%

Malwarebytes
PUP.Optional.InstallIQ.A
30.00%

Baidu Antivirus
Trojan.Win32.InstallIQ, Adware.Win32.InstallIQ
30.00%

Comodo Security
UnclassifiedMalware, Application.Win32.InstallIQ.NTZK
30.00%

Rising Antivirus
PE:PUF.InstallIQ!1.9E4F
20.00%

Trend Micro
Mal_Naix-5
20.00%

Prevx
High Risk Cloaked Malware
10.00%

Bkav FE
W32.Clod0ae.Trojan
10.00%

McAfee
Artemis!B4CD8262E255
10.00%

K7 AntiVirus
Unwanted-Program
10.00%

The domain dl2.iqdownload.com has been seen to resolve to the following 5 IP addresses.

August 25, 2016

February 4, 2016

January 4, 2016

cdn-208-111-161-254.iad.llnw.net
November 13, 2014

cdn-208-111-160-6.iad.llnw.net
November 13, 2014

File downloads found at URLs served by dl2.iqdownload.com.

18 / 68    (Adware)
http://dl2.iqdownload.com/lm/.../musicoasis.exe  (de4cf33ce6edb497c81d418f04ba26f6)

4 / 68      (Adware)

1 / 68      (Adware)
http://dl2.iqdownload.com/lm/.../jenkatarcade.exe  (56dd9b9319fc9645ba2082af87e10789)

1 / 68      (Adware)
http://dl2.iqdownload.com/lm/.../whales.exe  (d3ca96b35110c698a15f0a78876e30ee)

11 / 68    (Adware)
http://dl2.iqdownload.com/lm/.../musicoasis.exe  (dbe968bab086c039cb8dba341c4ffb30)

1 / 68      (Adware)
http://dl2.iqdownload.com/lm/.../intunemp3.exe  (3e9255c355c0e37c8aa1988fa5876293)

1 / 68      (Adware)
http://dl2.iqdownload.com/lm/.../whales.exe  ({721b8b78-117f-487b-b253-273868b383ff})

1 / 68      (Adware)
http://dl2.iqdownload.com/lm/.../Audacity_40.exe  (d1d26b270ac52981aa6984c975a5f903)

8 / 68      (Adware)
http://dl2.iqdownload.com/lm/.../facepaint.exe  (13d5865aa011019279c1ed87d21784d4)

1 / 68      (Adware)
http://dl2.iqdownload.com/lm/.../jenkatarcade.exe  (4d0f64a0aefd90a141146fd7c26b557b)

The following 87 files have been seen to comunicate with dl2.iqdownload.com in live environments.

 
Latest 20 of 137 files

URL:
http://dl2.iqdownload.com/

Google Analytics:
UA-2249740

Title:
“Iqdownload.com”

Description:
“Find Cash Advance, Debt Consolidation and more at Iqdownload.com. Get the best of Insurance or Free Credit Report, browse our section on Cell Phones or learn about Life Insurance. Iqdownload.com is the site for Cash Advance.”

Web server:
Microsoft-IIS/8.5 (ASP.NET) (Version: 4.0.30319)

30 of 685 related domains