download.pcupgradenow.com

AIR SOFTWARE INC.

Domain Information

The domain download.pcupgradenow.com registered by AIR SOFTWARE INC. was initially registered in March of 2014 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Strasbourg, Alsace within France which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Alsace, France (FR)

Create date:
Friday, March 14, 2014

Expires date:
Tuesday, March 14, 2017

Updated date:
Wednesday, April 6, 2016

ASN:
AS8972 PLUSSERVER-AS PlusServer AG,DE

Root domain:

Scanner detections:
Detections  (93% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.InstallManager.F, PUP.Air Software.InstallerSetup.Installer (M), PUP.Softpulse.DigitalPlugin.Bundler (M), PUP.Adknowledge.InstallManager.Installer (M), PUP.Adknowledge.InstallM.Installer (M), PUP.Bundlore.Wishapp.Bundler (M), PUP.Softpulse.DigitalP.Bundler (M), PUP.Air Software.AirSoftw.Bundler (M)
88.89%

Dr.Web
Trojan.SMSSend.5407, Trojan.SMSSend.5492, Trojan.SMSSend.5514, Trojan.SMSSend.5533
22.22%

ESET NOD32
Win32/AirAdInstaller.A potentially unwanted application
22.22%

avast!
Win32:Adware-BZI [PUP], Adware-gen [Adw], Win32:PUP-gen [PUP]
22.22%

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.153852, Gen:Variant.Adware.Graftor.163396
22.22%

F-Prot
W32/A-6bcf410b, W32/A-d0922a62, W32/A-ad198980, W32/Wegit.A.gen
22.22%

VIPRE Antivirus
Threat.4784938
18.52%

Malwarebytes
PUP.Optional.AirAdInstaller, PUP.Optional.AirInstaller, PUP.Optional.InstallManager
18.52%

NANO AntiVirus
Trojan.Win32.SMSSend.ddvfxt, Riskware.Win32.AirAdInstaller.dfkmlw, Riskware.Win32.AirAdInstaller.deojhu
18.52%

Agnitum Outpost
PUA.AirAd
18.52%

Avira AntiVirus
ADWARE/Adware.Gen
18.52%

Rising Antivirus
PE:PUF.Airinstall!1.9C4C
18.52%

AVG
Adware BundleApp_r, Generic
18.52%

McAfee
Trojan.Artemis!E30135681482
18.52%

Sophos
AirInstaller, PUA.AirInstaller
18.52%

The domain download.pcupgradenow.com has been seen to resolve to the following 3 IP addresses.

static-ip-62-75-207-166.inaddr.ip-pool.com
February 10, 2016

173.192.195.226-static.reverse.softlayer.com
September 27, 2014

empire.airinstaller.com
September 22, 2014

File downloads found at URLs served by download.pcupgradenow.com.

URL:
http://download.pcupgradenow.com/

Web server:
nginx/1.0.15 (PHP/5.3.3)

30 of 35 related domains