www.ifreeupdates.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.ifreeupdates.com is registered by proxy through GODADDY.COM, LLC and was originally registered in August of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Monday, August 11, 2014

Expires date:
Thursday, August 11, 2016

Updated date:
Tuesday, April 14, 2015

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US

Root domain:

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SalyutemPlyus.F, PUP.BestAPP.G, PUP.Amonetize, PUP.Outbrowse, PUP.Bundler.Adknowledge, PUP.Installer.Adknowledge, PUP.Bundler.Outbrowse, Threat.Outbrowse.Bundler, PUP.Adknowledge.Fileangels.Bundler (M), PUP.Outbrowse.ClickToStart.Bundler (M), PUP.Outbrowse.StartNow.Bundler (M), PUP.Outbrowse.FastDownloadgot.Installer (M), PUP.Adknowledge.DevelopInterface.Bundler (M), PUP.Adknowledge.Seekinstall.Installer (M), PUP.Outbrowse.YESAPPS.Bundler (M), PUP.Outbrowse.ClickYes.Bundler (M), PUP.Adknowledge.Seekinst.Bundler (M), PUP.Outbrowse.Outborwse.Installer (M), PUP.Adknowledge.Fileange.Bundler (M), PUP.Adknowledge.SafeDown.Bundler (M), PUP.Outbrowse.KAFORVAR.Installer (M), PUP.Outbrowse.Salyutem.Bundler (M), PUP.Adknowledge.DevelopI.Bundler (M), PUP.Outbrowse.Bundler, PUP.Outbrowse.Bundler (M), PUP.Outbrowse (M), PUP.Adknowledge (M)
100.00%

Avira AntiVirus
APPL/Outbrowse.Gen, APPL/OutBrowse.lwasp, ADWARE/iBryte.Gen7, PUA/Outbrowse.Gen, Adware/iBryte.bxpj, PUA/Outbrowse.lwasp
24.49%

Dr.Web
Trojan.OutBrowse.55, Adware.Downware.2081, Trojan.DownLoader12.28337, Trojan.OutBrowse.54, Trojan.DownLoader12.24188, Trojan.OutBrowse.58
22.45%

AVG
Downloader, Potentially harmful program Downloader.DGR, Generic, AdPlugin, Potentially harmful program Downloader.CPI, Adware AdPlugin.CMM
22.45%

Malwarebytes
PUP.Optional.OutBrowse, PUP.Optional.OptimunInstaller
20.41%

VIPRE Antivirus
Threat.4657539, Threat.4784459, Threat.4798837, Threat.4823950, Threat.4150696, Threat.4778314, Optimum Installer
20.41%

ESET NOD32
Win32/OutBrowse.BS potentially unwanted application, Win32/OutBrowse.AR potentially unwanted application, Win32/Adware.iBryte.CA application
20.41%

K7 AntiVirus
Trojan , Unwanted-Program , Adware
20.41%

NANO AntiVirus
Trojan.Win32.OutBrowse.dmiaid, Trojan.Win32.OutBrowse.dgnlgr, Riskware.Win32.ArchSMS.doctxi, Trojan.Win32.OutBrowse.dmikik
20.41%

G Data
Dropped:Application.Bundler.Outbrowse.AJ, Win32.Application.Outbrowse, Gen:Variant.Strictor.78910, Gen:Variant.Application.Bundler.Outbrowse
20.41%

McAfee
Artemis!521CB6738092, Adware-OutBrowse.e, Program.Adware-OutBrowse.a, Program.Adware-OutBrowse.c, Program.Adware-OutBrowse.e
18.37%

Sophos
Generic PUA ME, Generic PUA CC, PUA 'OutBrowse Revenyou', PUA 'iBryte Optimum Installer', Generic PUA HE, iBryte Premium Installer
18.37%

avast!
OutBrowse-G [PUP], Adware-gen [Adw], PUP-gen [PUP], Win32:IBryte-KG [PUP], Win32:IBryte-HN [PUP], Win32:PUP-gen [PUP]
18.37%

Comodo Security
Application.Win32.AltBrowse.HY, Application.Win32.AgentCV.HWYE, Application.Win32.OutBrowse.MQPC, Application.Win32.iBryte.BYK
18.37%

AhnLab V3 Security
PUP/Win32.OutBrowse, PUP/Win32.IBryte, PUP/Win32.OptimumInstaller
16.33%

The domain www.ifreeupdates.com has been seen to resolve to the following 2 IP addresses.

ip-50-63-202-55.ip.secureserver.net
August 17, 2016

charlie208.startdedicated.com
September 30, 2014

File downloads found at URLs served by www.ifreeupdates.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

23 / 68    (Adware)

 
Latest 30 of 61 download URLs

The following 992 files have been seen to comunicate with www.ifreeupdates.com in live environments.

 
Latest 20 of 992 files

URL:
http://www.ifreeupdates.com/

Title:
“Domain Default page”

Web server:
Apache (PleskLin)

30 of 35 related domains