leobells.blob.core.windows.net

Microsoft Corporation

Domain Information

The domain leobells.blob.core.windows.net registered by Microsoft Corporation was initially registered in August of 1995 through MARKMONITOR INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Tokyo, Tokyo within Japan which resides on the Microsoft Corporation network.
Registrar:
MARKMONITOR INC.

Server location:
Tokyo, Japan (JP)

Create date:
Thursday, August 10, 1995

Expires date:
Saturday, June 4, 2016

Updated date:
Wednesday, October 8, 2014

ASN:
AS8075 MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.InstallCore.Bundler (M), PUP.InstallCore.Internet.Installer.Meta (M), PUP.installCore (M), PUP.InstallCore (M), PUP.InstallCore.11 (M), PUP.InstallCore.RE11 (M), PUP.Bundler.Internet.Installer.Meta (M)
92.00%

Kaspersky
UDS:DangerousObject.Multi.Generic, not-a-virus:AdWare.Win32.DealPly
20.00%

Malwarebytes
PUP.Optional.InstallCore
16.00%

ESET NOD32
Win32/InstallCore.ACZ potentially unwanted (variant)
16.00%

VIPRE Antivirus
Threat.4439742
8.00%

AVG
InstallCore
4.00%

Total Defense
Heur/TrojanHorse.ZCKP!suspicious
4.00%

ESET NOD32
Win32/InstallCore.ACZ potentially unwanted application
4.00%

Bkav FE
HW32.Packed
4.00%

MicroWorld eScan
Gen:Variant.Application.Bundler.71
4.00%

Bitdefender
Gen:Variant.Application.Bundler.71
4.00%

Arcabit
Trojan.Application.Bundler.71
4.00%

Agnitum Outpost
PUA.DealPly
4.00%

F-Secure
Gen:Variant.Application.Bundler
4.00%

G Data
Gen:Variant.Application.Bundler.71
4.00%

The domain leobells.blob.core.windows.net has been seen to resolve to the following IP address.

blob.kw1prdstr01a.store.core.windows.net
September 16, 2015

File downloads found at URLs served by leobells.blob.core.windows.net.

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (e5f0f321c440072c7a81c5ae578a9145)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (297fb6b975b545046b42ee5891008b18)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (1925c435b3bd99e9469c1479636f5455)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (b7ee5a5a483272e06dec6c2384127ae8)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (8f3486b64a71e9c9bd8a3cdb65dfa99b)

3 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (94972804eda09ddaccf89b090df4d892)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (2016e95762e01c0444f9b3e462bd0114)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (691f1005e4ed8b4471072e0de78ae7bc)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (74a718611d19ba9bc505bc1f3617031d)

3 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (98c517d9c2b537466dfd6045ace31681)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (c6d0807080d2a7d9e14013f69ccb168b)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (7fa0ec48f41f24ba36ec12280da232a4)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (391bf81ad6a525c114a70546815cb8a6)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (9471d7c2f07712f62ec511228b44f1ee)

16 / 68    (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (1742bbbced9c23a4485940827a1dfb16)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (f874ba97cd3c3bb50aad487cd1dc14bd)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (b6ead4027ecddada7594ae683c1a6eb2)

4 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (f2b808c2ce4b74dc1e0245ea14004cc9)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (84198c8b476b35ed1349f039b1e67769)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (d84c65bd539e178f4496a1f0dd7fd11d)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (98f9ab239aeb32ce4cee6679ddb9a0b4)

2 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (dd581ee4175250ad507b1dc326dc43fc)

5 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (2165e368d0deb0ea7e472b671d125b26)

1 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (07991c82585fd8e45620c40cb4abdca8)

5 / 68      (PUP)
http://leobells.blob.core.windows.net/.../installer.exe  (8cbdf02ac3699bb556d4585b6fa7de25)

The following file have been seen to comunicate with leobells.blob.core.windows.net in live environments.

URL:
http://leobells.blob.core.windows.net/

SSL certificate subject:
CN=*.blob.core.windows.net

SSL certificate issuer:
CN=Microsoft IT SSL SHA2, OU=Microsoft IT, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Web server:
Microsoft-HTTPAPI/2.0