www.free-update.org

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain www.free-update.org is registered by proxy through PDR Ltd. d/b/a PublicDomainRegistry.com. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
PDR Ltd. d/b/a PublicDomainRegistry.com

Server location:
Northern Ireland, United Kingdom (GB)

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SuperCoolApplications.Q, PUP.installCore.SuperCoolApplications (M), PUP.installCore.SuperCoo (M), PUP.InstallCore.EST (M), PUP.installCore (M)
100.00%

ESET NOD32
Win32/InstallCore.JO potentially unwanted application, Win32/InstallCore.PK potentially unwanted application, Win32/InstallCore.AFF.gen potentially unwanted application, Win32/InstallCore.TU potentially unwanted application, Win32/InstallCore.OZ potentially unwanted application
26.00%

VIPRE Antivirus
Threat.4788237, Threat.4150696, Threat.5063361
22.00%

K7 AntiVirus
Unwanted-Program
18.00%

K7 Gateway Antivirus
Unwanted-Program
18.00%

Sophos
Install Core Click run software
18.00%

AVG
Max Setup
18.00%

McAfee Web Gateway
CryptInno, CryptInno!1D6C496F8489, BehavesLike.Win32.CryptInno.bc, BehavesLike.Win32.CryptInno.jc
16.00%

Dr.Web
infected with Trojan.Packed.24524, Trojan.MulDrop5.10078, Trojan.InstallCore.1903
14.00%

Malwarebytes
PUP.Optional.SuperCool, PUP.Optional.InstallCore
12.00%

Avira AntiVirus
Adware/InstallCore.iskd, Adware/InstallCore.A.588, Adware/InstallCore.JO.1, ADWARE/InstallCore.Gen9
10.00%

McAfee
CryptInno, CryptInno!1D6C496F8489, Program.CryptInno
8.00%

Comodo Security
Application.Win32.Installcore.SCL
6.00%

avast!
Win32:InstallCore-HH [PUP]
6.00%

Agnitum Outpost
PUA.InstallCore
2.00%

The domain www.free-update.org has been seen to resolve to the following 10 IP addresses.

ec2-52-10-193-58.us-west-2.compute.amazonaws.com
February 11, 2016

ec2-54-213-25-156.us-west-2.compute.amazonaws.com
February 11, 2016

ec2-54-69-189-98.us-west-2.compute.amazonaws.com
February 11, 2016

unallocated.barefruit.co.uk
July 31, 2014

ec2-54-186-198-136.us-west-2.compute.amazonaws.com
June 5, 2014

ec2-54-200-119-244.us-west-2.compute.amazonaws.com
June 5, 2014

ec2-54-201-15-32.us-west-2.compute.amazonaws.com
June 5, 2014

ec2-54-213-175-151.us-west-2.compute.amazonaws.com
June 5, 2014

ec2-54-186-46-235.us-west-2.compute.amazonaws.com
June 5, 2014

ec2-54-213-231-162.us-west-2.compute.amazonaws.com
June 5, 2014

File downloads found at URLs served by www.free-update.org.

 
Latest 30 of 57 download URLs

The following 230 files have been seen to comunicate with www.free-update.org in live environments.

 
Latest 20 of 230 files

URL:
http://www.free-update.org/

Web server:
nginx/1.4.3 (PHP/5.3.28)

Facebook:
Shares:  1

Statistics are for the previous month.