update-please.net

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain update-please.net is registered by proxy through REGISTRAR OF DOMAIN NAMES REG.RU LLC and was originally registered in November of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Zurich, Zurich within Switzerland which resides on the RIPE Network Coordination Centre network.
Registrar:
REGISTRAR OF DOMAIN NAMES REG.RU LLC

Server location:
Zurich, Switzerland (CH)

Create date:
Friday, November 7, 2014

Expires date:
Saturday, November 7, 2015

Updated date:
Friday, December 18, 2015

ASN:
AS40034 CONFLUENCE-NETWORK-INC - Confluence Networks Inc,VG

Google Safe Browsing:
phishing

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.DownloadFreeFriedCookie.L, PUP.Installer.DownloadFreeFriedCookie.R, PUP.Win.Reputation, PUP.Installer.ironSource, PUP.Installer.InstallCore.Installer, PUP.InstallCore.Installer.Installer (M), PUP.InstallCore.FC.Installer (M)
100.00%

ESET NOD32
Win32/InstallCore.RR potentially unwanted application, Win32/InstallCore.TU potentially unwanted application, Win32/InstallCore.TS potentially unwanted application
15.56%

AVG
Generic
15.56%

Dr.Web
Trojan.InstallCore.19
13.33%

VIPRE Antivirus
Threat.4786018
13.33%

Comodo Security
Application.Win32.FriedCookie.CIRK, Application.Win32.InstallCore.DQF
13.33%

Sophos
PUA 'InstallCore ToDownload'
11.11%

K7 AntiVirus
Unwanted-Program
11.11%

Avira AntiVirus
ADWARE/InstallCore.Gen7, PUA/InstallCore.Gen7
11.11%

NANO AntiVirus
Riskware.Win32.InstallCore.dlaypb, Trojan.Win32.InstallCore.dnxagv, Riskware.Win32.InstallCore.dqfxpi, Riskware.Win32.InstallCore.dmfogz
8.89%

G Data
Win32.Application.InstallCore.DI
8.89%

Agnitum Outpost
PUA.InstallCore
6.67%

Bkav FE
W32.HfsAdware
4.44%

Malwarebytes
PUP.Optional.InstallCore.SID.C
4.44%

Zillya! Antivirus
Downloader.MaintainSystem.Win32.4, Downloader.MaintainSystem.Win32.5
4.44%

The domain update-please.net has been seen to resolve to the following 2 IP addresses.

August 5, 2016

November 29, 2014

File downloads found at URLs served by update-please.net.

 
Latest 30 of 45 download URLs