software.installer-win.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain software.installer-win.com is registered by proxy through ENOM, INC. and was originally registered in May of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Digital Ocean, Inc. network.
Registrar:
ENOM, INC.

Server location:
New York, United States (US)

Create date:
Tuesday, May 12, 2015

Expires date:
Thursday, May 12, 2016

Updated date:
Tuesday, May 12, 2015

ASN:
AS393406 DIGITALOCEAN-ASN-NY3 - Digital Ocean, Inc.,US

Root domain:

Google Safe Browsing:
phishing

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Vittalia.Bundler, PUP.TVRon.tvronnet.Installer.Meta (M), PUP.Vittalia.InstallAssistant.Installer (M), PUP.Vittalia.InstallA.Installer (M), PUP.Air Software.AirSoftw.Bundler (M), PUP.Vittalia (M)
96.00%

F-Secure
Application:W32/Generic.70053c248f!Online, Adware.Eorezo.BZ
36.00%

Dr.Web
Adware.Downware.11360
36.00%

ESET NOD32
Win32/DownloadAssistant.A potentially unwanted application
36.00%

Lavasoft Ad-Aware
Gen:Trojan.Heur.JP.7u0@aODX1Cji, Gen:Variant.Graftor.185458, Gen:Trojan.Heur.JP.7u0@ayumrnfi
36.00%

Bkav FE
W32.HfsAdware
36.00%

MicroWorld eScan
Gen:Trojan.Heur.JP.7u0@auFSn6mi, Gen:Trojan.Heur.JP.7u0@ayumrnfi
36.00%

Malwarebytes
PUP.Optional.DownloadAssistant
36.00%

NANO AntiVirus
Trojan.Win32.Vittalia.dqfrig
36.00%

Avira AntiVirus
PUA/DownloadAssistant.Gen4
36.00%

AhnLab V3 Security
PUP/Win32.Downware
36.00%

AVG
Generic
36.00%

Zillya! Antivirus
Trojan.FakeAV.Win32.314885
36.00%

avast!
Xpaj-gen
32.00%

McAfee
Trojan.Artemis!7DBA5489C35D
32.00%

The domain software.installer-win.com has been seen to resolve to the following IP address.

useastone.pingdatanetwork.com
June 19, 2015

File downloads found at URLs served by software.installer-win.com.

1 / 68      (Adware)

1 / 68      (Adware)

2 / 68      (false positives)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

The following 4 files have been seen to comunicate with software.installer-win.com in live environments.

URL:
http://software.installer-win.com/

Web server:
Apache/2.4