absh.blob.core.windows.net
Microsoft Corporation
Domain Information
The domain absh.blob.core.windows.net registered by Microsoft Corporation was initially registered in August of 1995 through MARKMONITOR INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Microsoft Corporation network.
Registrant:
Microsoft Corporation
Registrar:
MARKMONITOR INC.
Server location:
Dublin City, Ireland (IE)
Create date:
Thursday, August 10, 1995
Expires date:
Saturday, June 4, 2016
Updated date:
Wednesday, October 8, 2014
ASN:
AS8075 MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation,US
Scanner detections:
Detections (96% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.InstallCore.Bundler (M), PUP.InstallCore.Internet.Installer.Meta (M), PUP.Installer.Bundler.Installer.Meta (M), PUP.installCore (M), PUP.InstallCore (M), PUP.InstallCore.S (M), PUP.InstallCore.RES (M), PUP.installCore.Program.Installer.Meta (M), PUP.Bundler (M)
84.62%
Malwarebytes
PUP.Optional.InstallCore
19.23%
ESET NOD32
Win32/InstallCore.ACZ potentially unwanted application
15.38%
Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
15.38%
ESET NOD32
Win32/InstallCore.ACZ potentially unwanted (variant)
3.85%
Fortinet FortiGate
Riskware/InstallCore
3.85%
Baidu Antivirus
Adware.Win32.InstallCore
3.85%
IKARUS anti.virus
AdWare.MSIL.Winusecu
3.85%
Qihoo 360 Security
HEUR/QVM06.1.Malware.Gen
3.85%
The domain absh.blob.core.windows.net has been seen to resolve to the following IP address.
blob.db5prdstr03a.store.core.windows.net
September 10, 2015
File downloads found at URLs served by absh.blob.core.windows.net.
The following 4 files have been seen to comunicate with absh.blob.core.windows.net in live environments.
URL:
http://absh.blob.core.windows.net/
SSL certificate subject:
CN=*.blob.core.windows.net
SSL certificate issuer:
CN=Microsoft IT SSL SHA2, OU=Microsoft IT, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Web server:
Microsoft-HTTPAPI/2.0