setting4upgrade.how2safeupdate.org

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain setting4upgrade.how2safeupdate.org is registered by proxy through Registrar of Domain Names REG.RU LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
Registrar of Domain Names REG.RU LLC

Server location:
Moscow City, Russia (RU)

ASN:
AS197695 AS-REGRU _Domain names registrar REG.RU_, Ltd,RU

Root domain:

Google Safe Browsing:
phishing

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.installCore.OOOADVERTM.Installer (M), PUP.installCore.OOOMadAdvert.Installer (M), PUP.installCore.OOOADVER.Installer (M), PUP.installCore.OOOAdver.Installer (M), PUP.installCore.OOOMadAd.Installer (M)
100.00%

AVG
Adware InstallCore
33.33%

Bkav FE
W32.HfsAdware
33.33%

ESET NOD32
Win32/InstallCore.YL potentially unwanted application, Win32/InstallCore.YK potentially unwanted application
25.00%

avast!
Malware-gen, Trojan-gen
25.00%

K7 AntiVirus
Adware
25.00%

Dr.Web
Trojan.InstallCore.508
25.00%

VIPRE Antivirus
Threat.4150696
25.00%

Avira AntiVirus
PUA/InstallCore.IB
16.67%

AhnLab V3 Security
PUP/Win32.Bundler
16.67%

Comodo Security
Application.Win32.InstallCore.DAF
16.67%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
16.67%

The domain setting4upgrade.how2safeupdate.org has been seen to resolve to the following 2 IP addresses.

March 1, 2016

February 22, 2016

File downloads found at URLs served by setting4upgrade.how2safeupdate.org.