download.screencapture.ru

Private Person  (Proxy Registrant)

Domain Information

The domain download.screencapture.ru is registered by proxy through REGGI-RU and was originally registered in April of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
REGGI-RU

Server location:
Moscow City, Russia (RU)

Create date:
Monday, April 16, 2012

Expires date:
Saturday, April 16, 2016

ASN:
AS199860 SDN-AS Stack Data Network LLC,RU

Root domain:

Scanner detections:
Detections  (80% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.iTVA.T, PUP.Installer.ITVA, PUP.iTVA.ITVALimitedLiabilityCompany.Installer.Meta (M)
80.00%

Dr.Web
Adware.Downware.6456, Adware.Downware.10462, Adware.Downware.12375
60.00%

ESET NOD32
Win32/Itva, Win32/Itva.D potentially unwanted (variant)
40.00%

McAfee
Artemis!2C315B2E5CF5
20.00%

K7 AntiVirus
Trojan
20.00%

Agnitum Outpost
Riskware.Agent
20.00%

NANO AntiVirus
Riskware.Win32.Downware.dgvnpv
20.00%

VIPRE Antivirus
Trojan.Win32.Generic
20.00%

IKARUS anti.virus
PUA.Itva
20.00%

Fortinet FortiGate
Riskware/Itva
20.00%

AVG
nbsp;
20.00%

Sophos
Generic PUA KC
20.00%

Zillya! Antivirus
Downloader.Agent.Win32.245868
20.00%

Vba32 AntiVirus
Downloader.Agent
20.00%

ESET NOD32
Win32/Itva.F potentially unwanted application
20.00%

The domain download.screencapture.ru has been seen to resolve to the following IP address.

November 30, 2014

File downloads found at URLs served by download.screencapture.ru.

1 / 68      (PUP)
http://download.screencapture.ru/screencapture_setup.exe  (d6f64cb87fe3930db4d9d51cdbdb15a1)

1 / 68      (inconclusive)
http://download.screencapture.ru/ScreenCaptureSetup.exe  (f660b14cec51f6448a843b4139372cb2)

4 / 68      (PUP)
http://download.screencapture.ru/ScreenCaptureSetup.exe  (58a62fd230a10c440c7b9db913b947cc)

3 / 68      (Adware)
http://download.screencapture.ru/ScreenCaptureSetupRU.exe  (133218b941ee2769046f3ce01fa89554)

12 / 68    (PUP)
http://download.screencapture.ru/ScreenCaptureSetupRU.exe  (2c315b2e5cf5d49a7b1e288cc64b92cd)

URL:
http://download.screencapture.ru/

Web server:
nginx/1.8.0

30 of 34 related domains