www.upgradienk.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain www.upgradienk.com is registered by proxy through ENOM, INC. and was originally registered in April of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Little Rock, Arkansas within the United States which resides on the Black Lotus Communications network.
Remove Malware from www.upgradienk.com - Powered by Reason Core Security
Registrar:
ENOM, INC.

Server location:
Arkansas, United States (US)

Create date:
Thursday, April 03, 2014

Expires date:
Friday, April 03, 2015

Updated date:
Thursday, April 03, 2014

ASN:
AS32421 BLCC - Black Lotus Communications

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.PaymentsInteractiveSL.E, PUP.Tuguu.PaymentsInteractive.Bundler (M)
100.00%

McAfee
Artemis!671C2FA09F6A, RDN/Generic PUP.x!c2r, CryptDomaIQ
57.14%

Malwarebytes
PUP.Optional.DomaIQ, PUP.Optional.BundleInstaller.A
57.14%

K7 AntiVirus
Unwanted-Program
57.14%

K7 Gateway Antivirus
Unwanted-Program
57.14%

Agnitum Outpost
PUA.DomaIQ, PUA.Lollipop
57.14%

avast!
Win32:Installer-AJ [PUP], Adware-gen [Adw], PUP-gen [PUP]
57.14%

Kaspersky
not-a-virus:AdWare.Win32.Lollipop
57.14%

Sophos
DomainIQ pay-per install
57.14%

Comodo Security
Application.Win32.DomaIQ.PUP
57.14%

Dr.Web
Adware.Downware.2532, Adware.Downware.2479
57.14%

VIPRE Antivirus
DomaIQ, Trojan.Win32.Generic, Threat.4783262
57.14%

Avira AntiVirus
APPL/DomaIQ.Gen, APPL/DomaIQ.A.10
57.14%

McAfee Web Gateway
Heuristic.BehavesLike.Win32.Suspicious.H, BehavesLike.Win32.CryptDoma.gh
57.14%

Kingsoft AntiVirus
Win32.Troj.Lollipop.ag.(kcloud), Win32.Troj.Lollipop.af.(kcloud)
57.14%

The domain www.upgradienk.com has been seen to resolve to the following IP address.

April 14, 2014

File downloads found at URLs served by www.upgradienk.com.

1 / 68      (Adware)
http://www.upgradienk.com/.../Java.exe  (bb4be05ef31ad48801f5aad8455e6553)

1 / 68      (Adware)
http://www.upgradienk.com/.../Java.exe  (a1a63774ed031742486a759db6fe2d6c)

1 / 68      (Adware)
http://www.upgradienk.com/.../Java.exe  (6b3a4060b98616a806252e98b0cd815d)

38 / 68    (Adware)
http://www.upgradienk.com/.../Java.exe  (26991b889bcd4d2f243a52fb9884c4d6)

33 / 68    (Adware)
http://www.upgradienk.com/.../Java.exe  (96fcb6cf7201aa64be995efd4ef69e3c)

31 / 68    (Adware)
http://www.upgradienk.com/.../Java.exe  (4fec566ac1253820eff1a83014b5923a)

19 / 68    (Adware)
http://www.upgradienk.com/.../Java.exe  (e96eb8bea35829b45f834958688c89a8)

URL:
http://www.upgradienk.com/

Google Analytics:
UA-69192

Title:
“upgradienk.com - Registered at Namecheap.com”

Web server:
nginx/1.6.2 (ASP.NET,ARR/2.5,ASP.NET) (Version: 4.0.30319)

Facebook:
Shares:  2

Statistics are for the previous month.

30 of 34 related domains

Remove Malware from www.upgradienk.com - Powered by Reason Core Security