dc101.4sharedhelper.com

China Capital Investment Limited

Domain Information

The domain dc101.4sharedhelper.com registered by China Capital Investment Limited was initially registered in August of 2015 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
LEATHERNECKDOMAINS.COM, LLC

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Tuesday, August 4, 2015

Expires date:
Thursday, August 4, 2016

Updated date:
Monday, March 7, 2016

ASN:
AS16265 LEASEWEB LeaseWeb B.V.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.NewITLimited.u, PUP.NewITLimited.R, PUP.New IT Limited.NewIT.Bundler (M), PUP.New IT Limited.ITMANAGE.Bundler (M), PUP.New IT Limited.NewIT (M), PUP.New IT Limited (M)
100.00%

McAfee
PUP-FIV!91886FA6C8CB
3.85%

Malwarebytes
PUP.Optional.4Shared
3.85%

K7 AntiVirus
Unwanted-Program
3.85%

Agnitum Outpost
PUA.4Shared
3.85%

avast!
FourShared-D [PUP]
3.85%

Comodo Security
Application.Win32.4Shared.G
3.85%

Dr.Web
Adware.Siggen.26344
3.85%

VIPRE Antivirus
4Shared
3.85%

Avira AntiVirus
APPL/Downloader.Gen6
3.85%

Sophos
4Share Downloader
3.85%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.85%

ESET NOD32
Win32/4Shared.C potentially unwanted application
3.85%

Rising Antivirus
PE:PUF.4Shared!1.9C25
3.85%

IKARUS anti.virus
nbsp;
3.85%

The domain dc101.4sharedhelper.com has been seen to resolve to the following 7 IP addresses.

192.230.92.93.ip.incapdns.net
August 7, 2016

199.83.132.93.ip.incapdns.net
June 25, 2016

April 6, 2016

March 3, 2016

February 24, 2016

hosted-by.leaseweb.com
July 3, 2014

c-r111-uc0058-141.webazilla.com
January 25, 2014

File downloads found at URLs served by dc101.4sharedhelper.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dc101.4sharedhelper.com:8080/downloadhelper/named/trinity2240_th/Wm_WY8K7/.../???????? ????????? feat. ??? ???????.exe  (แผลราตรี มิราคูลัส feat. เป้ อารักษ์.exe)

The following 6 files have been seen to comunicate with dc101.4sharedhelper.com in live environments.

URL:
http://dc101.4sharedhelper.com/

Web server:
nginx/1.8.1