The domain gosecureinstall.com registered by Whois Privacy Corp. was initially registered in March of 2014 through INTERNET.BS CORP.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network.
Registrant:
Whois Privacy Corp.
Registrar:
INTERNET DOMAIN SERVICE BS CORP
Server location:
Dublin City, Ireland (IE)
Create date:
Friday, March 21, 2014
Expires date:
Tuesday, March 21, 2017
Updated date:
Tuesday, March 22, 2016
ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.SETUPDOTEXE.F, PUP.Adknowledge.SETUPDOTEXE.Bundler (M), PUP.Adknowledge.SETUPDOT.Bundler (M), PUP.Adknowledge.WARPINST.Bundler (M), PUP.Adknowledge (M)
100.00%
Malwarebytes
PUP.Optional.OptimumInstaller.A
41.18%
NANO AntiVirus
Trojan.Win32.IBryte.cvsxum, Trojan.Win32.IBryte.cwtffl, Trojan.Win32.Agent.cvofrk, Trojan.Win32.Downware.cvgamb
41.18%
Kaspersky
not-a-virus:Downloader.Win32.Agent, HEUR:Trojan.Win32.Generic
41.18%
Comodo Security
TrojWare.Win32.IBryte.S, Application.Win32.IBryte.U
41.18%
Dr.Web
Trojan.Siggen6.12978, Adware.Downware.2505, Adware.Downware.2249, Trojan.Packed.28561
41.18%
VIPRE Antivirus
Optimum Installer, Threat.4778314, Trojan.Win32.Generic
41.18%
Avira AntiVirus
Adware/iBryte.A.7733, Adware/iBryte.bxjn, Adware/iBryte.qoemni, Adware/iBryte.qoemno
41.18%
Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, Downloader.Agent
41.18%
Rising Antivirus
PE:Malware.Agent!6.162B, PE:Malware.iBryte!6.14B5
41.18%
AVG
Skodna.Generic, Adware AdPlugin
41.18%
Panda Antivirus
Trj/Genetic.gen
41.18%
K7 AntiVirus
Unwanted-Program
41.18%
Sophos
iBryte Optimum Installer, PUA 'iBryte Optimum Installer'
41.18%
avast!
Win32:Adware-gen [Adw], Win32:Somoto-N [PUP]
41.18%
The domain gosecureinstall.com has been seen to resolve to the following 5 IP addresses.
ns1.ibspark.com
April 2, 2016
ec2-23-21-189-120.compute-1.amazonaws.com
July 14, 2014
ec2-54-243-244-249.compute-1.amazonaws.com
July 14, 2014
ec2-23-21-100-173.compute-1.amazonaws.com
April 30, 2014
ec2-50-17-234-52.compute-1.amazonaws.com
April 4, 2014
File downloads found at URLs served by gosecureinstall.com.
The following 142 files have been seen to comunicate with gosecureinstall.com in live environments.
Subdomains
URL:
http://gosecureinstall.com/
Title:
“gosecureinstall.com”