dc99.4sharedhelper.com

China Capital Investment Limited

Domain Information

The domain dc99.4sharedhelper.com registered by China Capital Investment Limited was initially registered in August of 2015 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Fort Lauderdale, Florida within the United States which resides on the WZ Communications Inc. network.
Registrar:
LEATHERNECKDOMAINS.COM, LLC

Server location:
Florida, United States (US)

Create date:
Tuesday, August 4, 2015

Expires date:
Thursday, August 4, 2016

Updated date:
Monday, March 7, 2016

ASN:
AS40824 WZCOM-US - WZ Communications Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.NewITLimited.e, PUP.NewITLimited.i, PUP.New IT Limited.NewIT.Bundler (M), PUP.New IT Limited.NewIT (M), PUP.New IT Limited.ITMANAGE.Bundler (M), PUP.New IT Limited (M)
100.00%

McAfee
PUP-FEP!92405BCD9295
6.25%

Malwarebytes
PUP.Optional.4Shared
6.25%

K7 AntiVirus
Unwanted-Program
6.25%

NANO AntiVirus
Trojan.Win32.StartPage.cqwdoj
6.25%

F-Prot
W32/4Shared.C2.gen
6.25%

avast!
Win32:FourShared-D [PUP]
6.25%

Agnitum Outpost
PUA.4Shared
6.25%

Comodo Security
Application.Win32.4Shared.G
6.25%

Dr.Web
Trojan.StartPage.54023
6.25%

VIPRE Antivirus
Trojan.Win32.Generic
6.25%

Avira AntiVirus
APPL/Downloader.Gen6
6.25%

Sophos
4Share Downloader
6.25%

G Data
Win32.Trojan-Downloader.Agent.BA
6.25%

AhnLab V3 Security
Adware/Win32.Downloader
6.25%

The domain dc99.4sharedhelper.com has been seen to resolve to the following 6 IP addresses.

192.230.92.93.ip.incapdns.net
August 5, 2016

199.83.132.93.ip.incapdns.net
July 31, 2016

April 15, 2016

March 4, 2016

February 24, 2016

c-r111-uc0056-139.webazilla.com
February 20, 2014

File downloads found at URLs served by dc99.4sharedhelper.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://dc99.4sharedhelper.com/downloadhelper/named/trinityep2230_th/E0jG6Nkn/.../?????????????????? - -???? ?????.exe  (ร้องไห้ใกล้หนองหาน - -ต่าย อรทัย.exe)

1 / 68      (Adware)

1 / 68      (Adware)

The following 7 files have been seen to comunicate with dc99.4sharedhelper.com in live environments.

URL:
http://dc99.4sharedhelper.com/

Web server:
nginx/1.8.1