update1024.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain update1024.com is registered by proxy through GODADDY.COM, LLC and was originally registered in January of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Garden City, New York within the United States which resides on the Webair Internet Development Company Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
New York, United States (US)

Create date:
Monday, January 11, 2016

Expires date:
Wednesday, January 11, 2017

Updated date:
Friday, February 5, 2016

ASN:
AS27257 WEBAIR-INTERNET - Webair Internet Development Company Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.STMSetup.R, PUP.installCore.STMSetup.Installer (M), PUP.InstallCore.Bundler (M), PUP.Installer (M), PUP.installCore (M), PUP (M)
100.00%

ESET NOD32
Win32/InstallCore.QC potentially unwanted application, Win32/InstallCore.OU potentially unwanted application, Win32/InstallCore.AFI.gen potentially unwanted application
12.50%

VIPRE Antivirus
Threat.4786018
12.50%

Dr.Web
Adware.InstallCore.386
9.38%

Malwarebytes
PUP.Optional.InstallCore, PUP.Optional.Bundle
9.38%

K7 AntiVirus
Unwanted-Program , Trojan
9.38%

Norman
InstallCore.CERT
9.38%

Sophos
Install Core Click run software
9.38%

Avira AntiVirus
ADWARE/InstallCore.Gen7, ADWARE/InstallCore.Gen9
9.38%

AVG
Generic
9.38%

AhnLab V3 Security
PUP/Win32.InstallCore
6.25%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
6.25%

Qihoo 360 Security
Malware.QVM06.Gen
6.25%

NANO AntiVirus
Riskware.Win32.InstallCore.dgyiew, Riskware.Win32.InstallCore.dhpyds
6.25%

The domain update1024.com has been seen to resolve to the following 3 IP addresses.

May 19, 2016

February 13, 2016

October 24, 2014

File downloads found at URLs served by update1024.com.

 
Latest 30 of 32 download URLs

URL:
http://update1024.com/

Title:
“Loading”

Web server:
nginx/1.8.0