dl5.iq11download.com

Corp New Ventures Services

Domain Information

The domain dl5.iq11download.com registered by Corp New Ventures Services was initially registered in December of 2015 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Road Town, British Virgin Islands within VG which resides on the Confluence Networks Inc network.
Registrar:
THIRDROUNDNAMES LLC

Server location:
British Virgin Islands, VG (VG)

Create date:
Tuesday, December 15, 2015

Expires date:
Thursday, December 15, 2016

Updated date:
Tuesday, December 22, 2015

ASN:
AS40034 CONFLUENCE-NETWORK-INC - Confluence Networks Inc,VG

Root domain:

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Win.Reputation, PUP.Installer.InstallX.K, PUP.Installer.InstallX.S, PUP.Installer.InstallX.N, PUP.Installer.InstallX.R, PUP.InstallX.Installer (M)
100.00%

ESET NOD32
Win32/InstallIQ (variant), Win32/InstallIQ.A potentially unwanted (variant)
91.67%

Malwarebytes
PUP.Optional.InstallIQ
87.50%

NANO AntiVirus
Riskware.Win32.Searcher.csnymk
87.50%

Avira AntiVirus
APPL/InstallIQ.Gen5
87.50%

VIPRE Antivirus
InstallIQ Installer, Trojan.Win32.Generic
87.50%

AVG
Generic, InstallIQ
87.50%

Kaspersky
not-a-virus:Downloader.NSIS.Agent
83.33%

Fortinet FortiGate
Riskware/Agent
83.33%

SUPERAntiSpyware
PUP.InstallIQ/Variant
79.17%

Trend Micro House Call
Suspicious_GEN.F47V0730, Suspicious_GEN.F47V0808, Suspicious_GEN.F47V0802, Suspicious_GEN.F47V0729, Suspicious_GEN.F47V0731
79.17%

Dr.Web
Adware.Downware.2512
79.17%

Comodo Security
UnclassifiedMalware, Application.Win32.InstallIQ.NTZK
66.67%

K7 AntiVirus
Adware , Trojan , Unwanted-Program
66.67%

Panda Antivirus
Trj/Chgt.C, Generic Suspicious, Trj/Genetic.gen
62.50%

The domain dl5.iq11download.com has been seen to resolve to the following 3 IP addresses.

January 4, 2016

May 4, 2015

August 17, 2014

File downloads found at URLs served by dl5.iq11download.com.

1 / 68      (Adware)
http://dl5.iq11download.com/lm/.../adorabless.exe  (31940ce385f7046c7700033a5ca7574a)

19 / 68    (Adware)

14 / 68    (Adware)

23 / 68    (Adware)

20 / 68    (Adware)

21 / 68    (Adware)
http://dl5.iq11download.com/lm/.../waterfalls1aw.exe  (dd27e45a3ba88260138a39eef4fbbc4f)

11 / 68    (Adware)
http://dl5.iq11download.com/lm/.../waterfallsii1aw.exe  (bf3a6301e67f5e767100ce453bbc878c)

26 / 68    (Adware)
http://dl5.iq11download.com/lm/.../marine2aw.exe  (6ef5a4fb71e15fd988d807e5c32380d9)

24 / 68    (Adware)
http://dl5.iq11download.com/lm/.../storm1aw.exe  (feafc852dffcce413856f95277906f86)

23 / 68    (Adware)
http://dl5.iq11download.com/lm/.../oceanlife.exe  (a31cdd890b7da84964e251e7716fbac5)

20 / 68    (Adware)
http://dl5.iq11download.com/lm/.../roses.exe  (59c1d250cd48b4c47cb04632244692ce)

23 / 68    (Adware)
http://dl5.iq11download.com/lm/.../3dfallingleavesawp.exe  (b666eaa5df1e42570fbb92e0cc9cd961)

15 / 68    (Adware)

19 / 68    (Adware)
http://dl5.iq11download.com/lm/.../passwordtrooper.exe  (5146af00809fe6d2b7c8d051196a59ee)

20 / 68    (Adware)
http://dl5.iq11download.com/lm/.../7Zip.exe  (30e26e10d72aee3bf0ff36fac4b462db)

21 / 68    (Adware)

1 / 68      (false positive)

2 / 68      (false positives)

20 / 68    (Adware)

17 / 68    (Adware)
http://dl5.iq11download.com/lm/.../expertpdf7.exe  (163533b74f5e25c38b50d6ed5bc88906)

14 / 68    (Adware)

11 / 68    (Adware)
http://dl5.iq11download.com/lm/.../musicoasis.exe  (d0bf53e3006609bfa619a12a956c4ad5)

18 / 68    (Adware)

18 / 68    (Adware)

The following 2 files have been seen to comunicate with dl5.iq11download.com in live environments.

URL:
http://dl5.iq11download.com/

Web server:
Apache