get.installmatic.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain get.installmatic.net is registered by proxy through GODADDY.COM, LLC and was originally registered in February of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Sao Paulo, Sao Paulo within Brazil which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrar:
GODADDY.COM, LLC

Server location:
Sao Paulo, Brazil (BR)

Create date:
Tuesday, February 19, 2013

Expires date:
Sunday, February 19, 2017

Updated date:
Thursday, January 28, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (91% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Bundler.Installmatic, PUP.Installmatic.UnilogicInformaticaaME (M), PUP.Installmatic.Unilogic (M)
90.91%

F-Secure
Application:W32/Generic.70053c248f!Online, Riskware.Gen:Variant.Application.Downloader
18.18%

Dr.Web
Trojan.Click3.11315, Trojan.Click3.9739
18.18%

VIPRE Antivirus
Threat.5062944
18.18%

avast!
Malware-gen, Win32:Malware-gen
18.18%

Norman
Gen:Variant.Graftor.156076, Gen:Variant.Strictor.62764
18.18%

Kaspersky
not-a-virus:Downloader.Win32.Agent
18.18%

Malwarebytes
PUP.Optional.MultiInstall.A
18.18%

Zillya! Antivirus
Downloader.Agent.Win32.241009, Downloader.Agent.Win32.238826
18.18%

K7 AntiVirus
Unwanted-Program
18.18%

NANO AntiVirus
Trojan.Win32.Agent.dphjjq, Trojan.Win32.Agent.dnxrhv
18.18%

Agnitum Outpost
PUA.Downloader
18.18%

G Data
Win32.Application.MultiInstall, Gen:Variant.Application.Downloader.190
18.18%

AhnLab V3 Security
PUP/Win32.MultiInstall
18.18%

IKARUS anti.virus
PUA.UltraDownloads
18.18%

The domain get.installmatic.net has been seen to resolve to the following IP address.

ec2-54-207-221-204.sa-east-1.compute.amazonaws.com
April 15, 2015

File downloads found at URLs served by get.installmatic.net.

1 / 68      (Adware)
http://get.installmatic.net/.../Mamae-Que-Nos-Faz.exe  (ddba1ad2734a78ce72bd9d88fd965334)

1 / 68      (Adware)
http://get.installmatic.net/.../Loki-Cola-Coca-Cola.exe  (c38706ff5ed17a75b6e7f50a4b76cfac)

1 / 68      (Adware)
http://get.installmatic.net/.../Hao123.exe  (1f3a62ab0ef3894b3b77a5674d63ab72)

1 / 68      (Adware)
http://get.installmatic.net/.../Ludo_311a.exe  (f194060e360ab4cec08b52e0dec8134e)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

2 / 68      (false positives)

25 / 68    (Adware)

18 / 68    (Adware)

The following 2 files have been seen to comunicate with get.installmatic.net in live environments.