dde.storage.dmccint.com

ClientConnect LTD

Domain Information

dmccint.com is the distribution web host for various Perion/Conduit monitization bundles. Typically an adware bundler will connect with the dmccint.com server to request various offers to display to the user (dynamic offer) based on certain properties of the user's PC. dmccint.com will also server a web page with offer details, mostly adware that will be embedded in the ClientConnect installer. The domain dde.storage.dmccint.com registered by ClientConnect LTD was initially registered in November of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Cambridge, Massachusetts within the United States which resides on the Akamai Technologies, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Massachusetts, United States (US)

Create date:
Thursday, November 21, 2013

Expires date:
Sunday, January 1, 2017

Updated date:
Tuesday, January 6, 2015

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ClientConnect.N, PUP.Installer.ClientConnect.G, Adware.Conduit (M), PUP.Conduit (M), PUP.Conduit.ClientCo.Installer (M), Adware.Conduit.Installer.Meta (M)
60.00%

ESET NOD32
Win32/Toolbar.Conduit.AB potentially unwanted application, Win32/Toolbar.Conduit.AE potentially unwanted application
58.00%

VIPRE Antivirus
Conduit, Threat.4786236, Threat.4150696, Trojan.Win32.Generic
30.00%

Kaspersky
not-a-virus:WebToolbar.Win32.Agent
24.00%

avast!
Win32:Evo-gen [Susp]
20.00%

Dr.Web
Adware.Conduit.43, - infected archive c:\users\test\appdata\local\temp\a17d9c5299fbdf8c47faee19083ccd7801ed4572 Trojan
14.00%

Malwarebytes
PUP.Optional.Conduit, PUP.Optional.ClientConnect
10.00%

ESET NOD32
Win32/Wajam (variant), Win32/Toolbar.Conduit.AB (variant), Win32/Toolbar.Conduit.AB potentially unwanted (variant), Win32/Toolbar.Conduit.AE potentially unwanted
10.00%

McAfee
Artemis!FBEFBAF24D27, RDN/Generic PUP.z, Artemis!8226938E06BC, Artemis!6B999C749BAA
8.00%

Fortinet FortiGate
Riskware/Toolbar_Conduit, Riskware/Conduit
6.00%

SUPERAntiSpyware
PUP.ClientConnect/Variant
6.00%

K7 AntiVirus
Trojan , Adware
6.00%

G Data
Win32.Application.Conduit, Win32.Application.Agent.T65UUY
6.00%

IKARUS anti.virus
PUA.ClientConnect
6.00%

AVG
Generic
6.00%

The domain dde.storage.dmccint.com has been seen to resolve to the following 53 IP addresses.

a23-219-88-143.deploy.static.akamaitechnologies.com
September 17, 2016

a23-219-88-153.deploy.static.akamaitechnologies.com
September 17, 2016

a23-219-88-209.deploy.static.akamaitechnologies.com
August 25, 2016

a23-219-88-198.deploy.static.akamaitechnologies.com
August 25, 2016

a184-51-126-107.deploy.static.akamaitechnologies.com
August 2, 2016

a184-51-126-106.deploy.static.akamaitechnologies.com
August 2, 2016

a104-96-220-169.deploy.static.akamaitechnologies.com
July 30, 2016

July 29, 2016

July 29, 2016

a104-96-221-146.deploy.static.akamaitechnologies.com
July 20, 2016

a104-96-221-89.deploy.static.akamaitechnologies.com
July 20, 2016

a104-96-220-160.deploy.static.akamaitechnologies.com
June 29, 2016

June 25, 2016

June 25, 2016

a23-215-133-34.deploy.static.akamaitechnologies.com
June 8, 2016

a23-215-133-57.deploy.static.akamaitechnologies.com
June 8, 2016

a184-28-17-210.deploy.static.akamaitechnologies.com
May 31, 2016

a104-96-220-144.deploy.static.akamaitechnologies.com
May 16, 2016

a104-96-220-97.deploy.static.akamaitechnologies.com
May 16, 2016

April 13, 2016

a184-28-17-201.deploy.static.akamaitechnologies.com
April 12, 2016

a184-28-17-202.deploy.static.akamaitechnologies.com
April 12, 2016

January 5, 2016

January 5, 2016

January 3, 2016

January 3, 2016

a23-67-243-59.deploy.static.akamaitechnologies.com
May 4, 2015

May 4, 2015

a23-3-13-32.deploy.static.akamaitechnologies.com
December 2, 2014

a23-3-13-35.deploy.static.akamaitechnologies.com
December 2, 2014

 
Showing 30 of 53 IP Addresses

File downloads found at URLs served by dde.storage.dmccint.com.

 
Latest 30 of 285 download URLs

The following 345 files have been seen to comunicate with dde.storage.dmccint.com in live environments.

 
Latest 20 of 405 files

URL:
http://dde.storage.dmccint.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET)