install.software-updates.co

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain install.software-updates.co is registered by proxy through GODADDY.COM, INC. and was originally registered in November of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the SoftLayer Technologies Inc. network.
Registrar:
GODADDY.COM, INC.

Server location:
Texas, United States (US)

Create date:
Sunday, November 4, 2012

Expires date:
Monday, November 3, 2014

Updated date:
Tuesday, July 1, 2014

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Bundlore.I, PUP.Optional.Installer.F, PUP.Air Software.AirSoftware.Bundler (M), PUP.Injekt.WesternWebApplications.Installer (M), PUP.Adknowledge.Fileangels.Bundler (M), PUP.Outbrowse.Bundler (M), PUP.Air Software.AirSoftw.Bundler (M), PUP.Softpulse.DIGITALP.Bundler (M), PUP.Solimba.Bechiro.Bundler (M), PUP.Air Software (M)
100.00%

Dr.Web
Adware.Downware.925, Program.Unwanted.79, Adware.Downware.963, Adware.iBryte.486, Adware.Downware.1167, Trojan.SMSSend.4953
26.53%

avast!
Win32:Bundlore-A [PUP], PUP-gen [PUP], Win32:Adware-gen [Adw]
24.49%

VIPRE Antivirus
Bundlore, AirInstaller, Threat.4778314, Threat.4782985, Threat.4150696
24.49%

AVG
LionSea Software co., Trojan horse Crypt2, AdPlugin, Adware Generic_r, InstallCore
24.49%

K7 AntiVirus
Adware , Unwanted-Program
22.45%

F-Prot
W32/AirInstall.A.gen, W32/A-34fffba4, W32/AirInstall.D.gen
22.45%

Sophos
AirInstaller, iBryte Premium Installer
22.45%

Comodo Security
Application.Win32.AirAdInstaller.A, Application.Win32.AgentCV.HWYE, Application.Win32.AirAdInstaller.B
22.45%

Avira AntiVirus
ADWARE/Adware.Gen7, ADWARE/iBryte.Gen4, Adware/AirInst.2556, Adware/AgentCV.A.6255
22.45%

G Data
Win32.Adware.Airadinstaller, Win32.Adware.IBryte
22.45%

nProtect
Trojan-Clicker/W32.AirAdInstaller.1116296, Trojan-Clicker/W32.iBryte.83312.E, Trojan-Clicker/W32.AirAdInstaller.1115272.B
22.45%

Kaspersky
not-a-virus:WebToolbar.Win32.Agent, Trojan.Win32.Badur, not-a-virus:HEUR:AdWare.Win32.Generic, not-a-virus:AdWare.Win32.AirAdInstaller
22.45%

NANO AntiVirus
Trojan.Win32.SMSSend.cwbmjp, Riskware.Win32.IBryte.desauy, Riskware.Win32.Downware.cwfgel, Riskware.Win32.AirAdInstaller.cwbyev
22.45%

IKARUS anti.virus
not-a-virus:WebToolbar.Win32.Agent, AdWare.AdPlugin, PUA.AirAdInstaller, Win32.SuspectCrc
22.45%

The domain install.software-updates.co has been seen to resolve to the following IP address.

173.192.117.66-static.reverse.networklayer.com
November 12, 2014

File downloads found at URLs served by install.software-updates.co.

URL:
http://install.software-updates.co/

Web server:
nginx (PHP/5.3.2-1ubuntu4.20)