2353a982c0ec4441be9797073bac2288.download.dmccint.com

ClientConnect LTD

Domain Information

dmccint.com is the distribution web host for various Perion/Conduit monitization bundles. Typically an adware bundler will connect with the dmccint.com server to request various offers to display to the user (dynamic offer) based on certain properties of the user's PC. dmccint.com will also server a web page with offer details, mostly adware that will be embedded in the ClientConnect installer. The domain 2353a982c0ec4441be9797073bac2288.download.dmccint.com registered by ClientConnect LTD was initially registered in November of 2013 through GODADDY.COM, LLC. This domain has been seen distributing various forms of adware (some being very aggressive) directly or via bundled installations. The hosted servers are located in San Mateo, California within the United States which resides on the Conduit USA, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
California, United States (US)

Create date:
Thursday, November 21, 2013

Expires date:
Sunday, January 1, 2017

Updated date:
Monday, May 4, 2015

ASN:
AS56473 CONDUIT-NL Conduit Connect B.V.

Root domain:

Scanner detections:
Adware distribution

Scan engine
Details
Detections

Microsoft Security Essentials
Worm:Win32/NeksMiner.A
50.00%

F-Secure
Application:W32/Generic.70053c248f!Online
50.00%

Malwarebytes
PUP.Optional.ClientConnect
50.00%

avast!
Win32:Adware-BRM [PUP]
50.00%

Kaspersky
not-a-virus:WebToolbar.Win32.Perinet
50.00%

NANO AntiVirus
Trojan.Win32.ClientConnect.deinfe
50.00%

Dr.Web
Adware.Downware.1895
50.00%

Zillya! Antivirus
Adware.Perinet.Win32.45
50.00%

Panda Antivirus
Trj/Chgt.C
50.00%

ESET NOD32
Win32/Toolbar.Conduit.AE
50.00%

IKARUS anti.virus
PUA.ClientConnect
50.00%

AVG
Generic
50.00%

Baidu Antivirus
Adware.Win32.Perinet
50.00%

Reason Heuristics
PUP.Perion.T
50.00%

The domain 2353a982c0ec4441be9797073bac2288.download.dmccint.com has been seen to resolve to the following IP address.

September 7, 2014

File downloads found at URLs served by 2353a982c0ec4441be9797073bac2288.download.dmccint.com.

URL:
http://2353a982c0ec4441be9797073bac2288.download.dmccint.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET)