dl.ke8u.com

xiao jie

Domain Information

The domain dl.ke8u.com registered by xiao jie was initially registered in July of 2014 through DOMAIN NAME NETWORK PTY LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dongguan, Guangdong within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
DOMAIN NAME NETWORK PTY LTD

Server location:
Guangdong, China (CN)

Create date:
Thursday, July 31, 2014

Expires date:
Monday, July 31, 2017

Updated date:
Thursday, January 8, 2015

ASN:
AS58543 CHINATELECOM-GUANGDONG-IDC Guangdong,CN

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (66% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Yantai (L), Adware.Downloader.YantaiZh.Installer.Meta (M), PUP.BeijingYuJinChengTechnologyCo.Installer (M)
47.83%

Clam AntiVirus
Win.Trojan.691128
39.13%

Fortinet FortiGate
Riskware/Generic.AC.18053, W32/Generic.AC.18053
34.78%

Dr.Web
Program.Unwanted.432, riskware program Program.Unwanted.1229, Adware.ShouQu.5, riskware program Program.Unwanted.432, Adware.ShouQu.5, Adware.ShouQu.22
34.78%

McAfee
Artemis!75CCA7BDF42A, Artemis!B0DCCCFBF21E, Artemis!DF3F315228C2, Artemis!4852A8AD1FB1, Artemis!A6AA6519CD72, Artemis!39353B5292EB
26.09%

avast!
Win32:Rootkit-gen [Rtk], Win32:Malware-gen, Win32:Evo-gen [Susp], Win32:Adware-gen [Adw]
26.09%

ESET NOD32
Win32/RiskWare.Yantai (variant), Win32/Baidu.C potentially unwanted, Win32/Packed.NSISmod.E suspicious (variant)
26.09%

IKARUS anti.virus
Win32.SuspectCrc, PUA.Generic
21.74%

AVG
Win32/DH, Generic
21.74%

ESET NOD32
Win32/Packed.NSISmod.E suspicious application, Win32/Adware.Xiaoxiong.A application, Win32/RiskWare.Yantai.A application
17.39%

Trend Micro House Call
Suspicious_GEN.F47V1115, Suspicious_GEN.F47V0123, Suspicious_GEN.F47V0603
13.04%

NANO AntiVirus
Riskware.Win32.ShouQu.dmnfjx
13.04%

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F], PE:Malware.Generic/QRS!1.9E2D [F], Adware.NSISmod!1.A1E0
13.04%

F-Prot
W32/Yantai.A.gen, W32/Linkury.C.gen
8.70%

Zillya! Antivirus
Adware.Linkury.Win32.51430, Adware.ShouQuCRTD.Win32.150
8.70%

The domain dl.ke8u.com has been seen to resolve to the following 7 IP addresses.

May 16, 2016

May 16, 2016

May 16, 2016

July 1, 2015

May 3, 2015

November 10, 2014

November 10, 2014

File downloads found at URLs served by dl.ke8u.com.

4 / 68      (PUP)

0 / 68

0 / 68
http://dl.ke8u.com/down.php?sid=358  (browser_v5.6.13381.207_r_4018_(build1606201920).exe)

5 / 68      (PUP)

8 / 68      (PUP)
http://dl.ke8u.com/down.php?sid=332  (â¸ãŸã§ã¥â°ã¦_417.exe)

0 / 68

5 / 68      (inconclusive)

1 / 68      (inconclusive)

1 / 68      (inconclusive)
http://dl.ke8u.com/down.php?sid=358  (5590b2ba_1202000051.exe)

1 / 68      (PUP)

1 / 68      (PUP)

0 / 68

7 / 68      (PUP)

1 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (PUP)

0 / 68

3 / 68      (PUP)

1 / 68      (PUP)

2 / 68      (PUP)

5 / 68      (PUP)

13 / 68    (PUP)

5 / 68      (PUP)

3 / 68      (PUP)

0 / 68
http://dl.ke8u.com/down.php?sid=333  (browser_v3.2.2766.0_r_4018_(build14112117).exe)

6 / 68      (Malware)

6 / 68      (Malware)

6 / 68      (PUP)

3 / 68      (PUP)

4 / 68      (inconclusive)

 
Latest 30 of 30 download URLs

The following 32 files have been seen to comunicate with dl.ke8u.com in live environments.

 
Latest 20 of 32 files

URL:
http://dl.ke8u.com/

Title:
“dl”

Web server:
nginx