maintainpc.whensoftisupdated.net

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain maintainpc.whensoftisupdated.net is registered by proxy through REGISTRAR OF DOMAIN NAMES REG.RU LLC and was originally registered in March of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Chicago, Illinois within the United States which resides on the SingleHop, Inc. network.
Registrar:
REGISTRAR OF DOMAIN NAMES REG.RU LLC

Server location:
Illinois, United States (US)

Create date:
Monday, March 23, 2015

Expires date:
Thursday, March 23, 2017

Updated date:
Thursday, March 24, 2016

ASN:
AS32475 SINGLEHOP-INC - SingleHop,US

Google Safe Browsing:
phishing

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.installCore.OOOMasterCode.Installer (M), PUP.OOOAdvertM.Installer (M), PUP.installCore (M), PUP.installCore.DigitalVei.Installer (M), PUP.InstallCore.48 (M), PUP.installCore.OOOMaste.Installer (M), PUP.InstallCore.RE48 (M), PUP.InstallCore (L)
94.12%

VIPRE Antivirus
Threat.4150696
17.65%

Dr.Web
Trojan.InstallCore.721, Trojan.InstallCore.703
17.65%

ESET NOD32
Win32/InstallCore.ZC potentially unwanted application
17.65%

AVG
Adware InstallCore.AIZ
17.65%

K7 AntiVirus
Adware
17.65%

NANO AntiVirus
Riskware.Win32.InstallCore.dsgvrb
17.65%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
17.65%

Avira AntiVirus
PUA/InstallCore.Gen
11.76%

avast!
Malware-gen
11.76%

Bkav FE
W32.HfsAdware
11.76%

Agnitum Outpost
PUA.InstallCore
5.88%

G Data
Win32.Application.InstallCore.EG
5.88%

The domain maintainpc.whensoftisupdated.net has been seen to resolve to the following 6 IP addresses.

lb-182-241.above.com
September 17, 2016

July 27, 2016

June 25, 2016

April 11, 2016

April 8, 2016

usdedi1.cipo.me
July 16, 2015

File downloads found at URLs served by maintainpc.whensoftisupdated.net.

The following 12 files have been seen to comunicate with maintainpc.whensoftisupdated.net in live environments.

URL:
http://maintainpc.whensoftisupdated.net/

Google Analytics:
UA-55552418

Title:
“Истёк срок регистрации доменаwhensoftisupdated.net”

Web server:
nginx

30 of 151 related domains