upgradecheck12.checkerweb.com

Code-M LTD

Domain Information

The domain upgradecheck12.checkerweb.com registered by Code-M LTD was initially registered in January of 2015 through REGISTRAR OF DOMAIN NAMES REG.RU LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Chicago, Illinois within the United States which resides on the SingleHop, Inc. network.
Registrar:
REGISTRAR OF DOMAIN NAMES REG.RU LLC

Server location:
Illinois, United States (US)

Create date:
Wednesday, January 14, 2015

Expires date:
Saturday, January 14, 2017

Updated date:
Friday, January 15, 2016

ASN:
AS32475 SINGLEHOP-INC - SingleHop,US

Root domain:

Google Safe Browsing:
phishing

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.installCore.Installer, PUP.installCore.OOOAdvertsDesign.Installer (M), PUP.installCore.OOOAdver.Installer (M), PUP.installCore (M)
100.00%

avast!
Malware-gen, Trojan-gen
59.09%

ESET NOD32
Win32/InstallCore.YK potentially unwanted application
59.09%

Dr.Web
Trojan.InstallCore.534, Trojan.InstallCore.206
59.09%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
59.09%

Bkav FE
W32.HfsAdware
59.09%

AVG
Adware InstallCore
59.09%

K7 AntiVirus
Adware
54.55%

Comodo Security
Application.Win32.InstallCore.DAF
36.36%

herdProtect (fuzzy)
a variant of 7abb43f80654d8baf249385a2b60f48dc7c606ea, a variant of 5ff6afa23a552e5ae812cae284b2eade159a232b, a variant of 41459f98bbe2a15e7ef21606ce7d590b2695b80a
27.27%

F-Secure
Adware.BrowseFox.BU
22.73%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
22.73%

NANO AntiVirus
Riskware.Win32.InstallCore.dqvwua
18.18%

Baidu Antivirus
Adware.Win32.InstallCore
9.09%

Avira AntiVirus
TR/Starter.Y
9.09%

The domain upgradecheck12.checkerweb.com has been seen to resolve to the following 3 IP addresses.

February 21, 2016

February 11, 2016

usdedi2.cipo.me
May 2, 2015

File downloads found at URLs served by upgradecheck12.checkerweb.com.

30 of 42 related domains