upgradecircle.checkupdateslive.net

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain upgradecircle.checkupdateslive.net is registered by proxy through REGISTRAR OF DOMAIN NAMES REG.RU LLC and was originally registered in February of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
REGISTRAR OF DOMAIN NAMES REG.RU LLC

Server location:
Moscow City, Russia (RU)

Create date:
Saturday, February 14, 2015

Expires date:
Tuesday, February 14, 2017

Updated date:
Sunday, February 14, 2016

ASN:
AS197695 AS-REGRU _Domain names registrar REG.RU_, Ltd,RU

Google Safe Browsing:
phishing

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.installCore.OOOADVERTMOBAIL.Installer (M), PUP.installCore.OOOADVERTM.Installer (M), PUP.installCore.OOOAdvertsDesign.Installer (M), PUP.installCore.OOOAdver.Installer (M), PUP.installCore.OOOADVER.Installer (M)
100.00%

avast!
Malware-gen, Trojan-gen
60.00%

Dr.Web
Trojan.InstallCore.534, Trojan.InstallCore.508, Trojan.InstallCore.206
60.00%

ESET NOD32
Win32/InstallCore.ZC potentially unwanted application, Win32/InstallCore.YL potentially unwanted application, Win32/InstallCore.YK potentially unwanted application
60.00%

K7 AntiVirus
Adware
60.00%

AVG
Generic, Adware InstallCore
60.00%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
60.00%

Comodo Security
Application.Win32.InstallCore.DFE, Application.Win32.InstallCore.DAF
40.00%

Bkav FE
W32.HfsAdware
40.00%

Malwarebytes
PUP.Optional.Bundle
20.00%

Avira AntiVirus
PUA/InstallCore.IB
20.00%

AhnLab V3 Security
PUP/Win32.Bundler
20.00%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
20.00%

The domain upgradecircle.checkupdateslive.net has been seen to resolve to the following IP address.

February 29, 2016

File downloads found at URLs served by upgradecircle.checkupdateslive.net.