24upgradecheck.freecheckupdates.net

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain 24upgradecheck.freecheckupdates.net is registered by proxy through REGISTRAR OF DOMAIN NAMES REG.RU LLC and was originally registered in February of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
REGISTRAR OF DOMAIN NAMES REG.RU LLC

Server location:
Moscow City, Russia (RU)

Create date:
Thursday, February 12, 2015

Expires date:
Sunday, February 12, 2017

Updated date:
Saturday, February 13, 2016

ASN:
AS197695 AS-REGRU _Domain names registrar REG.RU_, Ltd,RU

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.installCore.Installer, PUP.installCore.OOOAdvert.Installer (M), PUP.installCore.OOOAdver.Installer (M), PUP.installCore (M)
100.00%

avast!
Malware-gen
38.46%

Avira AntiVirus
PUA/InstallCore.A.2387
38.46%

Dr.Web
Trojan.InstallCore.206
38.46%

ESET NOD32
Win32/InstallCore.YN potentially unwanted application, Win32/InstallCore.YM potentially unwanted application
38.46%

K7 AntiVirus
Trojan
38.46%

AVG
InstallCore
38.46%

VIPRE Antivirus
Threat.4150696
38.46%

Bkav FE
W32.HfsAdware
38.46%

F-Secure
Gen:Variant.Kazy.576348
30.77%

Agnitum Outpost
PUA.InstallCore
30.77%

McAfee
Trojan.Artemis!841D2F484A2E
30.77%

herdProtect (fuzzy)
a variant of 64c3bf817a7940764b87e900b452c87241136a3a, a variant of 24c735dd333de747906915e5bcb25dbd5bc411cf
15.38%

G Data
Win32.Application.InstallCore.EG
15.38%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
15.38%

The domain 24upgradecheck.freecheckupdates.net has been seen to resolve to the following IP address.

February 16, 2016

File downloads found at URLs served by 24upgradecheck.freecheckupdates.net.