get.installmatic.net
Domains By Proxy, LLC (Proxy Registrant)
Domain Information
The domain get.installmatic.net is registered by proxy through GODADDY.COM, LLC and was originally registered in February of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Sao Paulo, Sao Paulo within Brazil which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrant:
Domains By Proxy, LLC
Registrar:
GODADDY.COM, LLC
Server location:
Sao Paulo, Brazil (BR)
Create date:
Tuesday, February 19, 2013
Expires date:
Sunday, February 19, 2017
Updated date:
Thursday, January 28, 2016
ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US
Scanner detections:
Detections (91% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Bundler.Installmatic, PUP.Installmatic.UnilogicInformaticaaME (M), PUP.Installmatic.Unilogic (M)
90.91%
F-Secure
Application:W32/Generic.70053c248f!Online, Riskware.Gen:Variant.Application.Downloader
18.18%
Dr.Web
Trojan.Click3.11315, Trojan.Click3.9739
18.18%
VIPRE Antivirus
Threat.5062944
18.18%
avast!
Malware-gen, Win32:Malware-gen
18.18%
Norman
Gen:Variant.Graftor.156076, Gen:Variant.Strictor.62764
18.18%
Kaspersky
not-a-virus:Downloader.Win32.Agent
18.18%
Malwarebytes
PUP.Optional.MultiInstall.A
18.18%
Zillya! Antivirus
Downloader.Agent.Win32.241009, Downloader.Agent.Win32.238826
18.18%
K7 AntiVirus
Unwanted-Program
18.18%
NANO AntiVirus
Trojan.Win32.Agent.dphjjq, Trojan.Win32.Agent.dnxrhv
18.18%
Agnitum Outpost
PUA.Downloader
18.18%
G Data
Win32.Application.MultiInstall, Gen:Variant.Application.Downloader.190
18.18%
AhnLab V3 Security
PUP/Win32.MultiInstall
18.18%
IKARUS anti.virus
PUA.UltraDownloads
18.18%
The domain get.installmatic.net has been seen to resolve to the following IP address.
ec2-54-207-221-204.sa-east-1.compute.amazonaws.com
April 15, 2015
File downloads found at URLs served by get.installmatic.net.
The following 2 files have been seen to comunicate with get.installmatic.net in live environments.