download.updatenowpro.com

REACTIVATION PERIOD

Domain Information

The domain download.updatenowpro.com registered by REACTIVATION PERIOD was initially registered in February of 2014 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Digital Ocean, Inc. network.
Registrar:
ENOM, INC.

Server location:
New York, United States (US)

Create date:
Tuesday, February 04, 2014

Expires date:
Thursday, February 04, 2016

Updated date:
Friday, March 18, 2016

ASN:
AS14061 DIGITALOCEAN-ASN - Digital Ocean, Inc.

Root domain:

Google Safe Browsing:
malware

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
DownloadManager.AirSoftware.F, PUP.Air Software.AirSoftware.Bundler (M), PUP.Air Software.AirSoftw.Bundler (M), PUP.Air Software (M)
100.00%

Avira AntiVirus
ADWARE/Adware.Gen
51.11%

Sophos
AirInstaller, PUA 'AirInstaller'
51.11%

Vba32 AntiVirus
AdWare.AirAdInstaller.ajov
51.11%

Rising Antivirus
PE:PUF.Airinstall!1.9C4C
51.11%

AVG
Generic_r, Adware Generic_r.JF
51.11%

IKARUS anti.virus
Win32.Malware
51.11%

AhnLab V3 Security
PUP/Win32.AirAdInstaller
51.11%

NANO AntiVirus
Riskware.Win32.AirAdInstaller.cwanhi, Riskware.Win32.AirAdInstaller.cwbkcs
51.11%

Jiangmin
AdWare/AirAdInstaller.jz, AdWare/AirAdInstaller.ji
51.11%

Antiy Labs AVL
GrayWare[AdWare:not-a-virus]/Win32.AirAdInstaller, Trojan[:HEUR]/Win32.AGeneric
51.11%

CMC Antivirus
AdWare.Win32.AirAdInstaller!O
51.11%

Qihoo 360 Security
Malware.QVM18.Gen, HEUR/Malware.QVM01.Gen
51.11%

nProtect
Trojan-Clicker/W32.AirAdInstaller.824744, Trojan-Clicker/W32.AirAdInstaller.862632
51.11%

F-Prot
W32/AirInstall.A8.gen, W32/A-8c0ea402
51.11%

The domain download.updatenowpro.com has been seen to resolve to the following 12 IP addresses.

192.230.92.93.ip.incapdns.net
August 6, 2016

199.83.132.93.ip.incapdns.net
June 24, 2016

June 2, 2016

May 30, 2016

May 17, 2016

February 8, 2016

static-ip-62-75-207-166.inaddr.ip-pool.com
January 31, 2016

108.168.218.35-static.reverse.softlayer.com
January 5, 2015

empire.airinstaller.com
August 10, 2014

173.192.195.228-static.reverse.softlayer.com
May 31, 2014

chicago.airinstaller.com
April 4, 2014

uswestmeganode1.airinstaller.com
March 18, 2014

File downloads found at URLs served by download.updatenowpro.com.

 
Latest 30 of 45 download URLs

The following 7 files have been seen to comunicate with download.updatenowpro.com in live environments.