phuwipwo.bl-up.ru

Private Person  (Proxy Registrant)

Domain Information

The domain phuwipwo.bl-up.ru is registered by proxy through REGRU-RU and was originally registered in September of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Nuremberg, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-RU

Server location:
Bayern, Germany (DE)

Create date:
Thursday, September 4, 2014

Expires date:
Friday, September 4, 2015

ASN:
AS24940 HETZNER-AS , DE

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.AZOVEKOGRUP.U, PUP.ProfitServis (M)
100.00%

VIPRE Antivirus
Threat.4150696
50.00%

ESET NOD32
Win32/InstallMonstr.HI potentially unwanted application
50.00%

Emsisoft Anti-Malware
Gen:Trojan.Heur.DP.@pNfaqi!oUbQ
50.00%

avast!
Win32:InstallMonstr-GC [PUP]
50.00%

Norman
Gen:Trojan.Heur.DP.@pNfaqi!oUbQ
50.00%

Lavasoft Ad-Aware
Gen:Trojan.Heur.DP.@pNfaqi!oUbQ
50.00%

Dr.Web
Trojan.InstallMonster.1052
50.00%

Sophos
PUA 'Install Monster'
50.00%

MicroWorld eScan
Gen:Trojan.Heur.DP.@pNfaqi!oUbQ
50.00%

K7 AntiVirus
Unwanted-Program
50.00%

Agnitum Outpost
Riskware.Agent
50.00%

Bitdefender
Gen:Trojan.Heur.DP.@pNfaqi!oUbQ
50.00%

F-Secure
Gen:Trojan.Heur.DP.@pNfaqi!oUbQ
50.00%

Avira AntiVirus
APPL/InstallMon.enib
50.00%

The domain phuwipwo.bl-up.ru has been seen to resolve to the following 2 IP addresses.

static.174.65.9.5.clients.your-server.de
September 5, 2016

November 29, 2014

File downloads found at URLs served by phuwipwo.bl-up.ru.

URL:
http://phuwipwo.bl-up.ru/

Web server:
nginx/1.4.2 (PHP/5.4.17)