get.win-install.com

FIRSERIA, S.L.  (via a Proxy Registrant)

Domain Information

The domain get.win-install.com is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2013. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Akamai Technologies, Inc. network. The domain is associated with the publisher FIRSERIA, S.L. who is located in Badalona, Barcelona in Spain.
Registrar:
GODADDY.COM, LLC

Server location:
New York, United States (US)

Create date:
Thursday, October 24, 2013

Expires date:
Friday, October 24, 2014

Updated date:
Monday, October 28, 2013

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Bechirosl.Q, PUP.Solimba.Bechiros.Installer (M), PUP.Solimba.Bechiros.Bundler (M)
100.00%

ESET NOD32
MSIL/Solimba.AH potentially unwanted application
25.00%

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Kazy.132995
25.00%

Dr.Web
Trojan.DownLoader11.24441
25.00%

VIPRE Antivirus
Threat.4150696
25.00%

MicroWorld eScan
Gen:Variant.Application.Bundler.Kazy.132995
25.00%

Malwarebytes
PUP.Optional.Solimba
25.00%

NANO AntiVirus
Trojan.Win32.Morstar.dersnn
25.00%

F-Prot
W32/A-a2151e6a
25.00%

Norman
Solimba.ZMKE
25.00%

Kaspersky
not-a-virus:Downloader.Win32.Morstar
25.00%

Bitdefender
Gen:Variant.Application.Bundler.Kazy.132995
25.00%

Agnitum Outpost
PUA.Solimba
25.00%

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Kazy.132995
25.00%

Comodo Security
Application.Win32.Solimba.LSW
25.00%

The domain get.win-install.com has been seen to resolve to the following 4 IP addresses.

a104-96-220-96.deploy.static.akamaitechnologies.com
May 17, 2016

a104-96-220-128.deploy.static.akamaitechnologies.com
May 17, 2016

a184-29-106-131.deploy.static.akamaitechnologies.com
September 28, 2014

a184-29-106-106.deploy.static.akamaitechnologies.com
September 28, 2014

File downloads found at URLs served by get.win-install.com.

1 / 68      (Adware)
http://get.win-install.com/n/3.1.24.5/.../Setup.exe  (308839725dbf35e26333ca559cee9b03)

1 / 68      (Adware)

1 / 68      (Adware)

26 / 68    (Adware)

The following 34 files have been seen to comunicate with get.win-install.com in live environments.

 
Latest 20 of 42 files

URL:
http://get.win-install.com/

Web server:
nginx (PHP/5.5.17)