dl2.vic0installer.com

NATIVEX HOLDINGS, LLC

Domain Information

The domain dl2.vic0installer.com registered by NATIVEX HOLDINGS, LLC was initially registered in January of 2014 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Wednesday, January 15, 2014

Expires date:
Thursday, January 15, 2015

Updated date:
Wednesday, August 20, 2014

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.InstallX.O, PUP.Installer.InstallX.M, PUP.Installer.InstallX.H, PUP.Installer.InstallX.K, PUP.Installer.InstallX.L, PUP.InstallX.SafeInstall.Installer (M), PUP.InstallX.SafeInst.Installer (M)
100.00%

Malwarebytes
PUP.Optional.SafeInstall.A
93.75%

NANO AntiVirus
Riskware.Win32.Searcher.csnymk
93.75%

Kaspersky
not-a-virus:Downloader.NSIS.Agent
93.75%

Comodo Security
Application.Win32.InstallIQ.B
93.75%

Dr.Web
Adware.Downware.2512, Threat.Undefined, Adware.Downware.9508
93.75%

VIPRE Antivirus
InstallIQ Installer, Threat.4783689
93.75%

Sophos
DomainIQ pay-per install, InstallQ (PUA)
93.75%

IKARUS anti.virus
PUA.InstallIQ, AdWare.InstallIQ
93.75%

AVG
Adware Generic_r.NT, Win32/Heur
93.75%

Panda Antivirus
Trj/Genetic.gen, Trj/CI.A, Trj/Chgt.E
93.75%

avast!
Rootkit-gen [Rtk], Adware-gen [Adw], Win32:Adware-gen [Adw], Win32:Rootkit-gen [Rtk]
93.75%

MicroWorld eScan
Application.Bundler.InstallIQ.D, Application.Bundler.CM, Gen:Variant.Application.Bundler.Graftor.155902
81.25%

McAfee
Artemis!5D04DCCE605B, PUP-FPB, Artemis!7BCDAC8AD2A7, Artemis!D4CA6B8D7BEB, Artemis!6BD4F1304872, Artemis!8BFD3FB965CF, Artemis!C5C59B3F4668
81.25%

K7 AntiVirus
Trojan , Adware , Unwanted-Program
81.25%

The domain dl2.vic0installer.com has been seen to resolve to the following 3 IP addresses.

unallocated.barefruit.co.uk
May 2, 2015

cdn-208-111-161-254.iad.llnw.net
September 1, 2014

cdn-208-111-160-6.iad.llnw.net
September 1, 2014

File downloads found at URLs served by dl2.vic0installer.com.

1 / 68      (Adware)

34 / 68    (Adware)

26 / 68    (Adware)

31 / 68    (Adware)

34 / 68    (Adware)

26 / 68    (Adware)

35 / 68    (Adware)

29 / 68    (Adware)

26 / 68    (Adware)

26 / 68    (Adware)

15 / 68    (Adware)

28 / 68    (Adware)

23 / 68    (Adware)

22 / 68    (Adware)

14 / 68    (Adware)

24 / 68    (Adware)

The following 315 files have been seen to comunicate with dl2.vic0installer.com in live environments.

 
Latest 20 of 365 files

URL:
http://dl2.vic0installer.com/

Title:
“Please Wait - You are being redirected.”

Web server:
nginx/1.0.15