www.update-srv.info

Red Online Marketing Group LP  (via a Proxy Registrant)

Domain Information

This is a distribution and communication domain for various adware from 215 Apps/50OnRed. The domain www.update-srv.info is registered by proxy through GoDaddy.com, LLC (R171-LRMS). This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Cambridge, Massachusetts within the United States which resides on the Akamai Technologies, Inc. network. The domain is associated with the publisher Red Online Marketing Group LP.
Registrar:
GoDaddy.com, LLC (R171-LRMS)

Server location:
Massachusetts, United States (US)

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.AppealingApps.J
100.00%

Dr.Web
Trojan.Crossrider.16835
100.00%

Zillya! Antivirus
Downloader.Psyme.VBS.1
100.00%

G Data
Win32.Adware.Smartapps
100.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
100.00%

ESET NOD32
Win32/AdWare.SmartApps
100.00%

The domain www.update-srv.info has been seen to resolve to the following 4 IP addresses.

May 12, 2014

May 12, 2014

May 8, 2014

a23-67-243-34.deploy.static.akamaitechnologies.com
May 8, 2014

File downloads found at URLs served by www.update-srv.info.

The following 288 files have been seen to comunicate with www.update-srv.info in live environments.

 
Latest 20 of 288 files

URL:
http://www.update-srv.info/

Web server:
nginx/1.4.1 (Ubuntu)