ip.installpack.net

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain ip.installpack.net is registered by proxy through ENOM, INC. and was originally registered in July of 2015. Currently this domain has been known to host various forms of malware. The hosted servers are located in Gunzenhausen, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Bayern, Germany (DE)

Create date:
Friday, July 3, 2015

Expires date:
Monday, July 3, 2017

Updated date:
Friday, July 3, 2015

ASN:
AS24940 HETZNER-AS Hetzner Online AG,DE

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
(M), Adware.Downloader.Alexande.Installer.Meta (M)
100.00%

Rising Antivirus
JS:Trojan.DL-Generic/JS!1.A4A8 [F]
6.67%

The domain ip.installpack.net has been seen to resolve to the following 3 IP addresses.

85-10-200-21.clients.your-server.de
April 22, 2016

static.85-10-196-94.clients.your-server.de
April 22, 2016

static.158.40.63.178.clients.your-server.de
April 22, 2016

File downloads found at URLs served by ip.installpack.net.

1 / 68      (PUP)

1 / 68      (Malware)
http://ip.installpack.net/InstallPack.exe  (installpack_n_4828b.exe)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (Malware)
http://ip.installpack.net/InstallPack.exe  (installpack_n_dc1ff.exe)

1 / 68      (PUP)
http://ip.installpack.net/InstallPack.exe  (installpack_n_f6399.exe)

1 / 68      (Malware)
http://ip.installpack.net/InstallPack.exe  (installpack_n_8d5d7.exe)

1 / 68      (Malware)
http://ip.installpack.net/InstallPack.exe  (installpack_n_da2a6.exe)

1 / 68      (Malware)
http://ip.installpack.net/InstallPack.exe  (installpack_n_0596c.exe)

1 / 68      (Malware)
http://ip.installpack.net/InstallPack.exe  (installpack_n_f1b53.exe)

1 / 68      (Malware)
http://ip.installpack.net/InstallPack.exe  (installpack_n_cefe7.exe)

1 / 68      (Malware)
http://ip.installpack.net/InstallPack.exe  (installpack_n_67f4a.exe)

2 / 68      (Malware)
http://ip.installpack.net/InstallPack.exe  (installpack_n_eec6c.exe)

1 / 68      (Malware)
http://ip.installpack.net/InstallPack.exe  (installpack_n_a4b38.exe)

1 / 68      (Malware)
http://ip.installpack.net/InstallPack.exe  (installpack_n_ebc3e.exe)

The following 7 files have been seen to comunicate with ip.installpack.net in live environments.

URL:
http://ip.installpack.net/

Web server:
nginx/1.8.0