The domain dl2.vic9installer.com registered by NATIVEX HOLDINGS, LLC was initially registered in January of 2014 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrant:
NATIVEX HOLDINGS, LLC
Server location:
Northern Ireland, United Kingdom (GB)
Create date:
Wednesday, January 15, 2014
Expires date:
Thursday, January 15, 2015
Updated date:
Wednesday, August 20, 2014
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.InstallX.O, PUP.Installer.InstallX.I, PUP.Installer.InstallX.E, PUP.InstallX.SafeInstall.Installer (M), PUP.InstallX.SafeInst.Installer (M)
100.00%
MicroWorld eScan
Gen:Variant.Application.Bundler.Graftor.155902
88.89%
Malwarebytes
PUP.Optional.SafeInstall.A
88.89%
K7 AntiVirus
Unwanted-Program
88.89%
Trend Micro House Call
Suspicious_GEN.F47V1118, Suspicious_GEN.F47V1119, Suspicious_GEN.F47V1115, TROJ_GEN.F0C2C00LH14, Suspicious_GEN.F47V1120
88.89%
avast!
Win32:Adware-gen [Adw], Win32:PUP-gen [PUP], Adware-CFF [PUP]
88.89%
Kaspersky
not-a-virus:Downloader.NSIS.Agent
88.89%
Bitdefender
Gen:Variant.Application.Bundler.Graftor.155902
88.89%
NANO AntiVirus
Riskware.Win32.Searcher.csnymk
88.89%
Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Graftor.155902
88.89%
Sophos
InstallQ, PUA 'InstallQ'
88.89%
Comodo Security
Application.Win32.InstallIQ.B
88.89%
F-Secure
Gen:Variant.Application.Bundler, Trojan.Downloader.JRJW
88.89%
Dr.Web
Adware.Downware.2512, Adware.Downware.9371, Threat.Undefined
88.89%
VIPRE Antivirus
InstallIQ Installer, Threat.4783689
88.89%
The domain dl2.vic9installer.com has been seen to resolve to the following 4 IP addresses.
unallocated.barefruit.co.uk
May 3, 2015
cdn-208-111-160-6.iad.llnw.net
November 29, 2014
cdn-208-111-161-254.iad.llnw.net
November 29, 2014
File downloads found at URLs served by dl2.vic9installer.com.
The following 315 files have been seen to comunicate with dl2.vic9installer.com in live environments.
URL:
http://dl2.vic9installer.com/
Title:
“Please Wait - You are being redirected.”