c5.97you.net

Xiamen Privacy Protection Service Co. Ltd.

Domain Information

The domain c5.97you.net registered by Xiamen Privacy Protection Service Co. Ltd. was initially registered in November of 2014 through ENAME TECHNOLOGY CO., LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Hangzhou, Zhejiang within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
ENAME TECHNOLOGY CO., LTD.

Server location:
Zhejiang, China (CN)

Create date:
Friday, November 14, 2014

Expires date:
Monday, November 14, 2016

Updated date:
Thursday, November 12, 2015

ASN:
AS37963 CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.,Ltd., CN

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Gen:Variant.Symmi.60792
100.00%

VIPRE Antivirus
Trojan.Win32.Generic
100.00%

Bitdefender
Gen:Variant.Symmi.60792
100.00%

K7 AntiVirus
Adware
100.00%

ESET NOD32
Win32/Gaofenquming.B potentially unwanted (variant)
100.00%

avast!
Win32:Malware-gen
100.00%

AegisLab AV Signature
Gen.Variant.Symmi!c
100.00%

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
100.00%

Lavasoft Ad-Aware
Gen:Variant.Symmi.60792
100.00%

F-Secure
Gen:Variant.Symmi.60792
100.00%

Emsisoft Anti-Malware
Gen:Variant.Symmi.60792
100.00%

Arcabit
Trojan.Symmi.DED78
100.00%

G Data
Gen:Variant.Symmi.60792
100.00%

IKARUS anti.virus
PUA.Gaofenquming
100.00%

Fortinet FortiGate
Riskware/Gaofenquming
100.00%

The domain c5.97you.net has been seen to resolve to the following 2 IP addresses.

August 23, 2016

July 8, 2016

File downloads found at URLs served by c5.97you.net.

15 / 68    (PUP)
http://c5.97you.net/.../????_35@20399.exe  (sogou_pinyin_79c_8100000377427033054.exe)

15 / 68    (PUP)
http://c5.97you.net/.../??????????v1.0_11@49831.exe  (sogou_pinyin_79c_8100000377427033054.exe)

15 / 68    (PUP)
http://c5.97you.net/.../Adobe_31@65071.exe  (sogou_pinyin_79c_8100000377427033054.exe)

15 / 68    (PUP)
http://c5.97you.net/.../???????_35@20249.exe  (sogou_pinyin_79c_8100000377427033054.exe)

15 / 68    (PUP)
http://c5.97you.net/.../Opera????_31@251157.exe  (sogou_pinyin_79c_8100000377427033054.exe)

15 / 68    (PUP)
http://c5.97you.net/.../????3D????2.0_11@136651.exe  (sogou_pinyin_79c_8100000377427033054.exe)

15 / 68    (PUP)
http://c5.97you.net/.../DotA_32@65940.exe  (sogou_pinyin_79c_8100000377427033054.exe)

URL:
http://c5.97you.net/

Web server:
nginx