dl2.vib7installer.com

NATIVEX HOLDINGS, LLC

Domain Information

The domain dl2.vib7installer.com registered by NATIVEX HOLDINGS, LLC was initially registered in January of 2014 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Thursday, January 2, 2014

Expires date:
Saturday, January 2, 2016

Updated date:
Thursday, December 10, 2015

Root domain:

Scanner detections:
Detections  (86% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Win.Reputation, PUP.Installer.InstallX.K, PUP.Installer.InstallX.W, PUP.Installer.InstallX.O, PUP.Installer.InstallX.J, PUP.InstallX.SafeInstall.Installer (M)
100.00%

ESET NOD32
Win32/InstallIQ (variant)
92.86%

AVG
Generic, MalSign.Generic, Generic_r, InstallIQ
92.86%

VIPRE Antivirus
InstallIQ Installer
85.71%

Comodo Security
Application.Win32.InstallIQ.B
85.71%

Dr.Web
Adware.Downware.2512, Adware.W3i.32, Adware.Downware.9371
85.71%

Sophos
InstallQ, DomainIQ pay-per install
85.71%

Malwarebytes
PUP.Optional.InstallIQ, PUP.Optional.SafeInstall.A
78.57%

NANO AntiVirus
Riskware.Win32.Searcher.csnymk
78.57%

Kaspersky
not-a-virus:Downloader.NSIS.Agent
71.43%

Bitdefender
Application.Bundler.InstallIQ.D, Gen:Variant.Application.Bundler.Graftor.155902
64.29%

G Data
Application.Bundler.InstallIQ, Win32.Application.InstallIQ
64.29%

McAfee
Artemis!9A0D0C8F9C89, Artemis!F85DB7EA0166, Artemis!A792379ADE2C, Artemis!84112AAF0BD9, Artemis!A80E20F31959, Artemis!9120CFF95355
57.14%

Trend Micro House Call
TROJ_GEN.F47V0415, TROJ_GEN.F47V0414, TROJ_GEN.F47V0421, Suspicious_GEN.F47V0816, Suspicious_GEN.F47V0820, Suspicious_GEN.F47V0818
57.14%

Qihoo 360 Security
HEUR/Malware.QVM06.Gen, Win32/Application.c39, Win32/Application.ab7
57.14%

The domain dl2.vib7installer.com has been seen to resolve to the following 6 IP addresses.

unallocated.barefruit.co.uk
May 15, 2016

December 23, 2015

cdn-208-111-160-6.iad.llnw.net
August 22, 2014

cdn-208-111-161-254.iad.llnw.net
August 22, 2014

May 30, 2014

May 30, 2014

File downloads found at URLs served by dl2.vib7installer.com.

2 / 68      (false positives)

21 / 68    (Adware)

1 / 68      (Adware)

34 / 68    (Adware)

22 / 68    (Adware)

22 / 68    (Adware)

28 / 68    (Adware)

29 / 68    (Adware)

21 / 68    (Adware)

1 / 68      (false positive)

2 / 68      (false positives)

23 / 68    (Adware)

15 / 68    (Adware)

17 / 68    (Adware)

The following 380 files have been seen to comunicate with dl2.vib7installer.com in live environments.

 
Latest 20 of 522 files

URL:
http://dl2.vib7installer.com/

Google Analytics:
UA-2249740

Title:
“Vib7installer.com”

Description:
“Find Cash Advance, Debt Consolidation and more at Vib7installer.com. Get the best of Insurance or Free Credit Report, browse our section on Cell Phones or learn about Life Insurance. Vib7installer.com is the site for Cash Advance.”

Web server:
nginx

30 of 685 related domains