beckywood.blob.core.windows.net

Microsoft Corporation

Domain Information

The domain beckywood.blob.core.windows.net registered by Microsoft Corporation was initially registered in August of 1995 through MARKMONITOR INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Bristow, Virginia within the United States which resides on the Microsoft Corp network.
Registrar:
MARKMONITOR INC.

Server location:
Virginia, United States (US)

Create date:
Thursday, August 10, 1995

Expires date:
Saturday, June 4, 2016

Updated date:
Wednesday, October 8, 2014

ASN:
AS8075 MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation,US

Root domain:

Scanner detections:
Detections  (80% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.InstallCore.Internet.Installer.Meta (M), PUP.installCore (M), PUP.InstallCore.RES (M)
80.00%

Bkav FE
HW32.Packed
20.00%

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48 [F]
20.00%

Panda Antivirus
Trj/Swizzor.S
20.00%

Qihoo 360 Security
QVM08.0.Malware.Gen
20.00%

The domain beckywood.blob.core.windows.net has been seen to resolve to the following IP address.

blob.bl2prdstr03a.store.core.windows.net
January 31, 2016

File downloads found at URLs served by beckywood.blob.core.windows.net.

1 / 68      (PUP)
http://beckywood.blob.core.windows.net/.../installer.exe  (3611e4fd32ccc61a01eba76ef0cab9a5)

4 / 68      (inconclusive)
http://beckywood.blob.core.windows.net/.../installer.exe  (7a833b2fb6d0bec7aee7a6332085e7b6)

1 / 68      (PUP)
http://beckywood.blob.core.windows.net/.../installer.exe  (98b09324e63e14fbc305365f3d47d3b8)

1 / 68      (PUP)
http://beckywood.blob.core.windows.net/.../installer.exe  (bfc022f60ce01b857c0335678352ce2f)

1 / 68      (PUP)
http://beckywood.blob.core.windows.net/.../installer.exe  (9274ac5ed1f32e06228646b9ba042ad1)

URL:
http://beckywood.blob.core.windows.net/

SSL certificate subject:
CN=*.blob.core.windows.net

SSL certificate issuer:
CN=Microsoft IT SSL SHA2, OU=Microsoft IT, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Web server:
Microsoft-HTTPAPI/2.0