download.windowsdefrag.ru

Private Person  (Proxy Registrant)

Domain Information

The domain download.windowsdefrag.ru is registered by proxy through RU-CENTER-RU and was originally registered in June of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
RU-CENTER-RU

Server location:
Moscow City, Russia (RU)

Create date:
Monday, June 23, 2014

Expires date:
Thursday, June 23, 2016

ASN:
AS199860 SDN-AS Stack Data Network LLC,RU

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.iTVA.U, PUP.iTVA.Installer (M)
100.00%

McAfee
Artemis!E6428C3F2A83
50.00%

K7 AntiVirus
Trojan
50.00%

Trend Micro House Call
Suspicious_GEN.F47V0924
50.00%

Agnitum Outpost
Riskware.Agent
50.00%

Sophos
Generic PUA DF
50.00%

Dr.Web
Adware.Downware.6456
50.00%

ESET NOD32
Win32/Itva
50.00%

IKARUS anti.virus
PUA.Itva
50.00%

Fortinet FortiGate
Riskware/Itva
50.00%

AVG
nbsp;
50.00%

The domain download.windowsdefrag.ru has been seen to resolve to the following IP address.

October 20, 2014

File downloads found at URLs served by download.windowsdefrag.ru.

1 / 68      (Adware)
http://download.windowsdefrag.ru/WindowsDefragSetupRU.exe  (83e685cf6fa2ee953f90b3b97c873600)

11 / 68    (PUP)
http://download.windowsdefrag.ru/WindowsDefragSetupRU.exe  (e6428c3f2a8392ac5f8a53c391d269b1)

URL:
http://download.windowsdefrag.ru/

Web server:
nginx/1.9.9

30 of 34 related domains