checksoft2upgrade.checkupdatenow.com

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain checksoft2upgrade.checkupdatenow.com is registered by proxy through REGISTRAR OF DOMAIN NAMES REG.RU LLC and was originally registered in January of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Registrar:
REGISTRAR OF DOMAIN NAMES REG.RU LLC

Server location:
Quebec, Canada (CA)

Create date:
Friday, January 30, 2015

Expires date:
Saturday, January 30, 2016

Updated date:
Friday, February 13, 2015

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ProfitServis.OOOPREMERSERVIS.Bundler (M), PUP.ProfitServis.OOOPREME.Bundler (M), PUP.Coinis.installCore.Installer (M)
100.00%

Dr.Web
Trojan.InstallCore.56
20.00%

K7 AntiVirus
Riskware
20.00%

Avira AntiVirus
ADWARE/InstallCore.Gen
20.00%

ESET NOD32
Win32/InstallCore.WV potentially unwanted (variant)
20.00%

avast!
Rootkit-gen [Rtk]
20.00%

VIPRE Antivirus
Trojan.Win32.Generic
20.00%

AVG
Generic
20.00%

F-Secure
Adware.SwiftBrowse.CR
20.00%

NANO AntiVirus
Riskware.Win32.InstallCore.dotkhj
20.00%

Agnitum Outpost
PUA.InstallCore
20.00%

Bkav FE
W32.HfsAdware
20.00%

Comodo Security
Application.Win32.InstallCore.DQR
20.00%

AhnLab V3 Security
PUP/Win32.InstallCore
20.00%

herdProtect (fuzzy)
a variant of d751126e87739e77149e7ae78cfabd1b1d546e6b
20.00%

The domain checksoft2upgrade.checkupdatenow.com has been seen to resolve to the following IP address.

ns513839.ip-167-114-156.net
May 19, 2016

File downloads found at URLs served by checksoft2upgrade.checkupdatenow.com.

The following 36 files have been seen to comunicate with checksoft2upgrade.checkupdatenow.com in live environments.

 
Latest 20 of 41 files