cdn1.upsa1a.com

Only contact by email, all postal mail will be rejected  (Proxy Registrant)

Domain Information

The domain cdn1.upsa1a.com is registered by proxy through SOLUCIONES CORPORATIVAS IP, SL and was originally registered in October of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Madrid, Madrid within Spain which resides on the RIPE Network Coordination Centre network.
Registrar:
SOLUCIONES CORPORATIVAS IP, SL

Server location:
Madrid, Spain (ES)

Create date:
Monday, October 13, 2014

Expires date:
Thursday, October 13, 2016

Updated date:
Tuesday, September 22, 2015

ASN:
AS45037 HISPAWEB-NETWORK Propelin Consulting S.L.U.,ES

Root domain:

Scanner detections:
Detections  (80% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Updater.Installer.Meta (M), PUP.DownloadAdmin (M)
45.00%

Kaspersky
UDS:DangerousObject.Multi.Generic, not-a-virus:AdWare.Win32.Agent
40.00%

ESET NOD32
Win32/Vittalia.W potentially unwanted application, Win32/Vittalia.Z potentially unwanted application
30.00%

Trend Micro House Call
Suspicious_GEN.F47V0120, TROJ_GEN.R047H05AF15, Suspicious_GEN.F47V1231, Suspicious_GEN.F47V0205, Suspicious_GEN.F47V0111
30.00%

ESET NOD32
Win32/Vittalia, Win32/Vittalia.W potentially unwanted
30.00%

Baidu Antivirus
PUA.Win32.Vittalia
30.00%

avast!
Win32:Dropper-gen [Drp], Win32:Malware-gen
25.00%

K7 AntiVirus
Trojan
25.00%

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
10.00%

McAfee
Artemis!F7C718E19886, Artemis!5451CA2ED92C
10.00%

NANO AntiVirus
Trojan.Win32.Vittalia.dncoce
10.00%

Rising Antivirus
PE:Malware.Adwapper!6.243A
5.00%

Sophos
Generic PUA MO
5.00%

F-Prot
W32/Trojan2.OYVN (exact, not disinfectable)
5.00%

G Data
Win32.Trojan.Agent.ILV9GH
5.00%

The domain cdn1.upsa1a.com has been seen to resolve to the following IP address.

February 22, 2016

File downloads found at URLs served by cdn1.upsa1a.com.

9 / 68      (PUP)

5 / 68      (PUP)

3 / 68      (inconclusive)
http://cdn1.upsa1a.com/tdtjpd.exe  (updinstaller.exe)

1 / 68      (PUP)
http://cdn1.upsa1a.com/tdtjpd.exe  (updinstaller.exe)

1 / 68      (inconclusive)
http://cdn1.upsa1a.com/tdtjpd.exe  (d819ee91a3507ed4f26df04233b988b0)

1 / 68      (PUP)
http://cdn1.upsa1a.com/tdtjpd.exe  (updinstaller.exe)

3 / 68      (PUP)

1 / 68      (inconclusive)

8 / 68      (PUP)

7 / 68      (PUP)
http://cdn1.upsa1a.com/tdtjpd.exe  (4d02b8a63b827c81d0a28175754f7c4f)

2 / 68      (PUP)

1 / 68      (inconclusive)
http://cdn1.upsa1a.com/tdtjpd.exe  (237c607c40f7a58b57603bd35dc386d5)

7 / 68      (PUP)
http://cdn1.upsa1a.com/tdtjpd.exe  (f7c718e19886cfe64592d0ac02be588a)

1 / 68      (PUP)
http://cdn1.upsa1a.com/tdtjpd.exe  (updinstaller.exe)

5 / 68      (PUP)

1 / 68      (PUP)
http://cdn1.upsa1a.com/tdtjpd.exe  (updinstaller.exe)

1 / 68      (PUP)
http://cdn1.upsa1a.com/tdtjpd.exe  (updinstaller.exe)

1 / 68      (PUP)
http://cdn1.upsa1a.com/tdtjpd.exe  (updinstaller.exe)

2 / 68      (PUP)
http://cdn1.upsa1a.com/tdtjpd.exe  (21cd8c9e15549432495d1afa4c13f44c)

1 / 68      (PUP)
http://cdn1.upsa1a.com/tdtjpd.exe  (updinstaller.exe)