www.ocrtoword.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain www.ocrtoword.com is registered by proxy through ENOM, INC. and was originally registered in April of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Houston, Texas within the United States which resides on the ThePlanet.com Internet Services, Inc. network.
Registrar:
ENOM, INC.

Server location:
Texas, United States (US)

Create date:
Wednesday, April 11, 2012

Expires date:
Tuesday, April 11, 2017

Updated date:
Monday, March 14, 2016

ASN:
AS21844 THEPLANET-AS - ThePlanet.com Internet Services, Inc.

Root domain:

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.N, PUP.OpenCandy.Installer (L), PUP.Bundler.TsingsoftImaginationInformationTechnologyCo.Installer.Meta (L), Win32.Generic
100.00%

ESET NOD32
Win32/InstallMonetizer.AF, Win32/Adware.RK.AP, Win32/OpenCandy (variant), Win32/InstallCore.QL (variant), Win32/InstallCore.PY (variant), Win32/OpenCandy.C potentially unsafe (variant)
68.18%

VIPRE Antivirus
InstallCore, Threat.4786018
50.00%

Norman
InstallCore.CERT
45.45%

Avira AntiVirus
ADWARE/InstallCore.Gen9, Adware/InstallCore.692760, ADWARE/InstallCore.Gen7
36.36%

K7 AntiVirus
Trojan , Unwanted-Program
36.36%

Dr.Web
Trojan.InstallCore.11
36.36%

Baidu Antivirus
Adware.Win32.InstallCore
31.82%

Sophos
Generic PUA NC, Generic PUA HN, Generic PUA EO, Generic PUA MF, Generic PUA AK, Generic PUA BK
27.27%

Fortinet FortiGate
Riskware/InstallCore
27.27%

McAfee
Artemis!2306BD47C1B3, Artemis!D027CD87018F, Artemis!57425AD9A933, Artemis!7C2C9AB90A46, Artemis!6EE49044B88C, Artemis!6E07B12682FC
27.27%

Trend Micro House Call
Suspicious_GEN.F47V0821, Suspicious_GEN.F47V1117, Suspicious_GEN.F47V0107, Suspicious_GEN.F47V0119, Suspicious_GEN.F47V0214
22.73%

Comodo Security
ApplicUnwnt
22.73%

Malwarebytes
PUP.Optional.Amonetize
18.18%

F-Prot
W32/InstallCore.AC.gen
13.64%

The domain www.ocrtoword.com has been seen to resolve to the following 2 IP addresses.

184.173.227.114-static.reverse.softlayer.com
May 3, 2015

67.81.7bae.static.theplanet.com
April 16, 2014

File downloads found at URLs served by www.ocrtoword.com.

1 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (6ea981eea60b942023cdc5c062c750f0)

3 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (2a8dd3a0acdb0029293b8e0e75f7aee2)

1 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (71da1a1acde4c69d537fe6ef310428d1)

0 / 68
http://www.ocrtoword.com/FreeOCRtoWord.exe  (57b24951da4341ed5b76d7af632e445d)

3 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (aca834e6795f7b47b073647dc4cc09b0)

3 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (8fef649750151c1ba49f2f73ff0e3019)

12 / 68    (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (6ee49044b88c1bb89d698e3b9fc1440c)

10 / 68    (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (icreinstall_freeocrtoword.exe)

12 / 68    (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (57425ad9a9335b1a4034a7c5f11f6c6d)

13 / 68    (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (7c2c9ab90a46ca352fa306f977d8f61e)

6 / 68      (PUP)

6 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (4621e79c7ad427bbcd7250389e327181)

8 / 68      (PUP)

5 / 68      (PUP)

5 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (69c655cff588327a493cf00f90b0ecdd)

13 / 68    (PUP)

8 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (6e07b12682fc6d378648983d98516b24)

8 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (efddc6474cb893a7e0991a1925dda169)

1 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (4725bdc1b934883dd0dd2bc43ff78e80)

13 / 68    (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (d027cd87018f61a35fa726c36228207b)

13 / 68    (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (2306bd47c1b3968beac185d2f0f37762)

13 / 68    (PUP)

1 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (2d8b1817bf3720936d67ea221d66b827)

1 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (48745377711cc843258852375503ae72)

2 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (0624dcb3ed6d1e5c3ac8473d03da9dbb)

2 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (4d5f297999d88693f1ba8a519bd52731)

2 / 68      (PUP)
http://www.ocrtoword.com/FreeOCRtoWord.exe  (95cab08931ad6aed102c5a718bed7faa)

The following 8 files have been seen to comunicate with www.ocrtoword.com in live environments.

URL:
http://www.ocrtoword.com/

Google Analytics:
UA-30955106

Title:
“TechCandy Software - Free OCR to Word - Easy Free OCR Image to Word Converter”

Description:
“Our free OCR to Word converter enables you to convert images to Word with high accuracy.”

Web server:
Apache/2.4.7 (PHP/5.5.9-1ubuntu4.14)

Facebook:
Likes:  8
Shares:  314
Comments:  13

Statistics are for the previous month.