www.packetinstalls.info

Wired 2000 Corporation

Domain Information

Currently this domain has been known to host various forms of malware. The hosted servers are located in Marietta, Georgia within the United States which resides on the NationalNet, Inc. network.
Registrar:
eNom, Inc.

Server location:
Georgia, United States (US)

ASN:
AS22384 NATIONALNET-1 - NationalNet, Inc.,US

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

VIPRE Antivirus
DownloadAdmin, Threat.4150696, Trojan.Win32.Generic
83.33%

Trend Micro House Call
TROJ_GEN.F47V0701, TROJ_GEN.F47V0314, TROJ_GEN.R0CCH06KK13, TROJ_GEN.R0CBC0PHF14
66.67%

Dr.Web
Adware.Downware.644, Trojan.DownLoader9.24960, Trojan.DownLoader9.25938, Trojan.DownLoader9.9637
66.67%

Baidu Antivirus
Trojan.Win32.Agent, Trojan.Win32.Pincav, HackTool.Win32.Downloader
50.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, Downloader.Agent
50.00%

McAfee
Artemis!81AAC44F7DE6, RDN/Generic Downloader.x!gz, Artemis!D6CD628FBA07
50.00%

Malwarebytes
PUP.DownloadAdmin, Trojan.Agent
33.33%

NANO AntiVirus
Trojan.Win32.Downware.bvyxhe, Trojan.Win32.Generic.bzwzlo
33.33%

ESET NOD32
Win32/DownloadAdmin, Win32/InstallMonetizer.AL
33.33%

Reason Heuristics
PUP.DownloadAdmin.K, PUP.Tightrope.DownloadAdmin.Bundler (M)
33.33%

Kaspersky
Trojan.Win32.Pincav, not-a-virus:Downloader.NSIS.Agent
33.33%

Rising Antivirus
PE:Trojan.Win32.Generic.157FAFE9!360689641, PE:Trojan.Win32.Generic.158029C8!360720840
33.33%

Fortinet FortiGate
W32/Tfr.DK!tr, Riskware/NSIS_Agent
33.33%

Qihoo 360 Security
Win32/Trojan.67a, Win32/Virus.Downloader.9ef
33.33%

AVG
Skodna.Bundle
16.67%

The domain www.packetinstalls.info has been seen to resolve to the following IP address.

February 9, 2016

File downloads found at URLs served by www.packetinstalls.info.

21 / 68    (PUP)
http://www.packetinstalls.info/.../IMSetup.exe  (d6cd628fba07e0770e6b151da04518fc)

9 / 68      (Adware)
http://www.packetinstalls.info/.../clocksaver.exe  (70127b7258a5a9c22b1cbf1c01da5aa0)

11 / 68    (Malware)
http://www.packetinstalls.info/.../w3iDownloader.exe  (81aac44f7de6de5143aa0fb0c2200799)

8 / 68      (Malware)
http://www.packetinstalls.info/.../IMSetup.exe  (8f1af0038496ac5d251f405b5c0ca7f2)

5 / 68      (Malware)
http://www.packetinstalls.info/.../BabylonDownloader.exe  (8a50e5530d2b4f3c91a8b3f700206df5)

1 / 68      (Adware)
http://www.packetinstalls.info/.../clocksaver.exe  (8b2f805d9c0f1bcf7ef567fb44ef6984)

URL:
http://www.packetinstalls.info/

Title:
“Free Chat Rooms Online”

Web server:
Apache/2.2.22 (Debian)