The domain wiseconvert.com registered by Name Management Group was initially registered in January of 2012 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Chicago, Illinois within the United States which resides on the GigeNET network.
Registrant:
Name Management Group
Registrar:
GODADDY.COM, LLC
Server location:
Illinois, United States (US)
Create date:
Saturday, January 28, 2012
Expires date:
Saturday, January 28, 2017
Updated date:
Wednesday, March 30, 2016
Scanner detections:
Detections (96% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Conduit.O, PUP.Installer.ClientConnect.F, PUP.4327.Conduit.O, PUP.4605.Conduit.O, PUP.Conduit.Installer, PUP.Conduit.49019.Bundler, PUP.Conduit.Bundler (M), PUP.Perion.Bundler.Conduit.Installer (M), PUP.Perion.Bundler.Conduit (M), Win32.Generic, PUP.Perion.Bundler (M)
100.00%
Dr.Web
Adware.Conduit.3, Adware.Conduit.87, Adware.BGuard.15, Threat.Undefined, Adware.Conduit.6, Adware.InstallCore.101, Adware.InstallCore.122
20.83%
VIPRE Antivirus
Threat.4786236, Conduit
18.75%
Malwarebytes
PUP.Optional.Conduit.A, PUP.Optional.ClientConnect
14.58%
Trend Micro House Call
TROJ_GEN.F47V0522, TROJ_GEN.F47V0529, Suspicious_GEN.F47V0624, Suspicious_GEN.F47V0722, TROJ_GEN.F47V1103, TROJ_GEN.F47V0910
12.50%
avast!
Win32:Adware-BRM [PUP], Win32:Adware-gen [Adw], Win32:Installer-I [PUP]
12.50%
AVG
Generic, Potentially harmful program Toolbar.Conduit
12.50%
McAfee
Artemis!1BC6B9E64145, Artemis!63AD372E1DDC, Artemis!C5BB48AE8A2E, Artemis!D2E5A7B3F531, Artemis!03AB4BA7799B
10.42%
Baidu Antivirus
Adware.Win32.Conduit, Trojan.Win32.ClientConnect
10.42%
Fortinet FortiGate
Riskware/Toolbar_Conduit, Riskware/ClientConnect
10.42%
ESET NOD32
Win32/Toolbar.Conduit.AE, Win32/ClientConnect (variant), Win32/OpenCandy
10.42%
ESET NOD32
Win32/Toolbar.Conduit.M potentially unwanted application, Win32/Toolbar.Conduit.AJ potentially unwanted application, Win32/InstallCore.BL potentially unwanted application
8.33%
NANO AntiVirus
Riskware.Win32.Conduit.czvfwi, Riskware.Win32.BGuard.csnycu, Trojan.Win32.ClientConnect.deinfe
6.25%
F-Prot
W32/InstallCore.R.gen
6.25%
Panda Antivirus
PUP/Conduit.A
4.17%
The domain wiseconvert.com has been seen to resolve to the following 5 IP addresses.
ip-69.39.236.56.hosted.by.gigenet.com
June 2, 2016
ip-50-63-202-52.ip.secureserver.net
February 8, 2016
184.173.251.169-static.reverse.softlayer.com
December 27, 2013
File downloads found at URLs served by wiseconvert.com.
The following 418 files have been seen to comunicate with wiseconvert.com in live environments.
Subdomains
URL:
http://wiseconvert.com/