up.updateinstant.com

New Age Soft LTD

Domain Information

The domain up.updateinstant.com registered by New Age Soft LTD was initially registered in December of 2014 through REGISTRAR OF DOMAIN NAMES REG.RU LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Zurich, Zurich within Switzerland which resides on the RIPE Network Coordination Centre network.
Registrar:
REGISTRAR OF DOMAIN NAMES REG.RU LLC

Server location:
Zurich, Switzerland (CH)

Create date:
Wednesday, December 31, 2014

Expires date:
Thursday, December 31, 2015

Updated date:
Wednesday, December 31, 2014

ASN:
AS19905 NEUSTAR-AS6 - NeuStar, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.InstallCore.Installer, PUP.Outbrowse.TikiTaka.Bundler (M), PUP.OutBrowse (M)
100.00%

ESET NOD32
Win32/InstallCore.SO potentially unwanted application, Win32/OutBrowse.BQ potentially unwanted application
50.00%

Dr.Web
Trojan.InstallCore.31, Trojan.BPlug.1006
50.00%

VIPRE Antivirus
Threat.4786018, Threat.4150696
50.00%

McAfee
Trojan.Artemis!14089DCA3DD5, Program.Adware-OutBrowse.e
50.00%

Malwarebytes
PUP.Optional.FriedCookie
25.00%

Avira AntiVirus
Adware/InstallCore.A.338
25.00%

AVG
Generic
25.00%

Sophos
PUA 'Install Core Click run software'
25.00%

K7 AntiVirus
Trojan
25.00%

Total Defense
Win32/Tnega.GFNWHJC
25.00%

Agnitum Outpost
PUA.InstallCore
25.00%

Comodo Security
Application.Win32.FriedCookie.CIRK
25.00%

G Data
Win32.Application.InstallCore.DI
25.00%

NANO AntiVirus
Trojan.Win32.InstallCore.dlzdza
25.00%

The domain up.updateinstant.com has been seen to resolve to the following 2 IP addresses.

April 21, 2016

January 25, 2015

File downloads found at URLs served by up.updateinstant.com.

The following 2 files have been seen to comunicate with up.updateinstant.com in live environments.

URL:
http://up.updateinstant.com/

Title:
“updateinstant.com”

Web server:
Apache