www.kurulumtr.com

Whois Privacy Protection Service.

Domain Information

The domain www.kurulumtr.com registered by Whois Privacy Protection Service. was initially registered in February of 2013 through NICS TELEKOMUNIKASYON TICARET LTD.STI.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Paris, Ile-De-France within France which resides on the RIPE Network Coordination Centre network.
Registrar:
NICS TELEKOMUNIKASYON TICARET LTD.STI.

Server location:
Ile-De-France, France (FR)

Create date:
Thursday, February 14, 2013

Expires date:
Saturday, February 14, 2015

Updated date:
Tuesday, February 4, 2014

ASN:
AS12322 PROXAD Free SAS

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Trend Micro House Call
TROJ_SPNR.08KE13, TROJ_FAKEAV.BMC, TROJ_GEN.R0CBC0PB914
100.00%

avast!
Win32:PUP-gen [PUP]
100.00%

Comodo Security
Application.Win32.InstallCore.~A, Application.Win32.Agent.~HO, Application.Win32.InstallCore.~LO
100.00%

McAfee
RDN/Generic.hra!bt, RDN/Generic PUP.x!bq3, Artemis!4C0F70836418
100.00%

Malwarebytes
Adware.Agent.IC
100.00%

K7 AntiVirus
Trojan , Unwanted-Program
100.00%

Sophos
Install Core Click run software
100.00%

Dr.Web
Trojan.DownLoader10.41344, Adware.InstallCore.144, Trojan.DownLoader9.3893
100.00%

VIPRE Antivirus
Trojan.Win32.Generic
100.00%

Avira AntiVirus
Adware/InstallCore.AI, ADWARE/InstallCore.Gen7
100.00%

Trend Micro
TROJ_SPNR.08KE13, TROJ_FAKEAV.BMC, TROJ_GEN.R0CBC0PB914
100.00%

AhnLab V3 Security
Trojan/Win32.Spnr, Win32/ChiHack.6652
100.00%

ESET NOD32
Win32/InstallCore.FJ (variant), Win32/InstallCore.IJ (variant), Win32/InstallCore.BY (variant)
100.00%

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
100.00%

Fortinet FortiGate
W32/Hra.BT!tr, Riskware/InstallCore, Riskware/MultiPlug
100.00%

The domain www.kurulumtr.com has been seen to resolve to the following 2 IP addresses.

195-154-168-124.rev.poneytelecom.eu
September 4, 2014

88-190-61-124.poneytelecom.eu
December 27, 2013

File downloads found at URLs served by www.kurulumtr.com.

40 / 68    (PUP)
http://www.kurulumtr.com/Baba 3 -.exe  (daemon_tools_lite.exe)

29 / 68    (PUP)

40 / 68    (PUP)

40 / 68    (PUP)

40 / 68    (PUP)

20 / 68    (PUP)
http://www.kurulumtr.com/Internet Download Manager.exe  (İnternet_Download_Manager.exe)

20 / 68    (PUP)
http://www.kurulumtr.com/Internet Download Manager.exe  (İnternet_Download_Manager.exe)

URL:
http://www.kurulumtr.com/

Title:
“KURULUMTR - ndirme / Download Reklamlar”

Description:
“KURULUM TR, ndirme ve Download ierikli reklamlar sunan kaliteli bir firmadr. Kurulumtr.com”

Web server:
Apache/2.2.25 (Unix) mod_ssl/2.2.25 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635