testpconly12.theupgradenow.com

GreenSoft LTD

Domain Information

The domain testpconly12.theupgradenow.com registered by GreenSoft LTD was initially registered in January of 2015 through REGISTRAR OF DOMAIN NAMES REG.RU LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
REGISTRAR OF DOMAIN NAMES REG.RU LLC

Server location:
Moscow City, Russia (RU)

Create date:
Monday, January 26, 2015

Expires date:
Thursday, January 26, 2017

Updated date:
Wednesday, January 27, 2016

ASN:
AS197695 AS-REGRU _Domain names registrar REG.RU_, Ltd,RU

Root domain:

Google Safe Browsing:
phishing

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ProfitServis.OOOPREMERSERVIS.Bundler (M)
100.00%

avast!
Rootkit-gen [Rtk]
100.00%

VIPRE Antivirus
Threat.4150696
100.00%

Dr.Web
Trojan.InstallCore.56
100.00%

ESET NOD32
Win32/InstallCore.WC potentially unwanted application, Win32/InstallCore.WV potentially unwanted application
100.00%

Bkav FE
W32.HfsAdware
100.00%

K7 AntiVirus
Trojan , Riskware
100.00%

NANO AntiVirus
Riskware.Win32.InstallCore.dotkie, Riskware.Win32.InstallCore.dotkhj
100.00%

Comodo Security
Application.Win32.InstallCore.KG, Application.Win32.InstallCore.DQR
100.00%

Avira AntiVirus
PUA/InstallCore.Gen9, ADWARE/InstallCore.Gen
100.00%

AVG
Generic
100.00%

Malwarebytes
PUP.Optional.InstallCore.A
100.00%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
100.00%

F-Secure
Adware.SwiftBrowse.CR
50.00%

Agnitum Outpost
PUA.InstallCore
50.00%

The domain testpconly12.theupgradenow.com has been seen to resolve to the following IP address.

February 10, 2016

File downloads found at URLs served by testpconly12.theupgradenow.com.