download.oneinstaller.com

Only contact by email, all postal mail will be rejected  (Proxy Registrant)

Domain Information

The domain download.oneinstaller.com is registered by proxy through SOLUCIONES CORPORATIVAS IP, SL and was originally registered in January of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Madrid, Madrid within Spain which resides on the RIPE Network Coordination Centre network.
Registrar:
SOLUCIONES CORPORATIVAS IP, SL

Server location:
Madrid, Spain (ES)

Create date:
Tuesday, January 15, 2013

Expires date:
Sunday, January 15, 2017

Updated date:
Monday, December 14, 2015

ASN:
AS45037 HISPAWEB-NETWORK Propelin Consulting S.L.U.,ES

Root domain:

Scanner detections:
Detections  (91% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MaxSetup.L, Threat.Installer.OneInstaller, PUP.InstallCore (M), PUP.Vittalia.OneInstaller (M), PUP.Vittalia.OneInsta.Bundler (M), PUP.installCore.MaxSetup (M), PUP.Vittalia (M)
90.00%

K7 AntiVirus
Trojan , Adware , Unwanted-Program
40.00%

NANO AntiVirus
Riskware.Win32.InstallCore.dfglmk, Trojan.Win32.Siggen5.cthmqx
40.00%

Agnitum Outpost
PUA.InstallCore, Riskware.Agent
40.00%

Dr.Web
Trojan.Packed.24524, Adware.Downware.1265, Trojan.MulDrop5.10078
40.00%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4786531, Threat.4788237
40.00%

G Data
Win32.Application.InstallCore, NSIS.Adware.Lollipop
40.00%

IKARUS anti.virus
Backdoor.Win32.Hupigon, PUA.Lollipop
40.00%

Qihoo 360 Security
Win32/Virus.Adware.94c, Trojan.Generic
40.00%

F-Prot
W32/InstallCore.AD.gen
30.00%

Trend Micro House Call
TROJ_GEN.R0C1C0OLQ14, Suspicious_GEN.F47V0723, Suspicious_GEN.F47V0217
30.00%

Sophos
Install Core Click run software, Generic PUA OO
30.00%

Avira AntiVirus
ADWARE/InstallCore.Gen7
30.00%

McAfee
Artemis!300D0E302EB1, Artemis!E1CC237A7F7C, Artemis!E450A7E12EE6
30.00%

Vba32 AntiVirus
Downware.InstallCore
30.00%

The domain download.oneinstaller.com has been seen to resolve to the following IP address.

oneinstaller.com
January 23, 2015

File downloads found at URLs served by download.oneinstaller.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

18 / 68    (Adware)

0 / 68
http://download.oneinstaller.com/.../?iid=592&nsoft=14  (non confirmé 838244.crdownload)

1 / 68      (Adware)

28 / 68    (PUP)

14 / 68    (Adware)

26 / 68    (Adware)

The following 6 files have been seen to comunicate with download.oneinstaller.com in live environments.

URL:
http://download.oneinstaller.com/

Web server:
Apache/2.2.22 (Ubuntu)