The domain dl.ke8u.com registered by xiao jie was initially registered in July of 2014 through DOMAIN NAME NETWORK PTY LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dongguan, Guangdong within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
DOMAIN NAME NETWORK PTY LTD
Server location:
Guangdong, China (CN)
Create date:
Thursday, July 31, 2014
Expires date:
Monday, July 31, 2017
Updated date:
Thursday, January 8, 2015
ASN:
AS58543 CHINATELECOM-GUANGDONG-IDC Guangdong,CN
Google Safe Browsing:
unwanted
Scanner detections:
Detections (66% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Yantai (L), Adware.Downloader.YantaiZh.Installer.Meta (M), PUP.BeijingYuJinChengTechnologyCo.Installer (M)
47.83%
Clam AntiVirus
Win.Trojan.691128
39.13%
Fortinet FortiGate
Riskware/Generic.AC.18053, W32/Generic.AC.18053
34.78%
Dr.Web
Program.Unwanted.432, riskware program Program.Unwanted.1229, Adware.ShouQu.5, riskware program Program.Unwanted.432, Adware.ShouQu.5, Adware.ShouQu.22
34.78%
McAfee
Artemis!75CCA7BDF42A, Artemis!B0DCCCFBF21E, Artemis!DF3F315228C2, Artemis!4852A8AD1FB1, Artemis!A6AA6519CD72, Artemis!39353B5292EB
26.09%
avast!
Win32:Rootkit-gen [Rtk], Win32:Malware-gen, Win32:Evo-gen [Susp], Win32:Adware-gen [Adw]
26.09%
ESET NOD32
Win32/RiskWare.Yantai (variant), Win32/Baidu.C potentially unwanted, Win32/Packed.NSISmod.E suspicious (variant)
26.09%
IKARUS anti.virus
Win32.SuspectCrc, PUA.Generic
21.74%
AVG
Win32/DH, Generic
21.74%
ESET NOD32
Win32/Packed.NSISmod.E suspicious application, Win32/Adware.Xiaoxiong.A application, Win32/RiskWare.Yantai.A application
17.39%
Trend Micro House Call
Suspicious_GEN.F47V1115, Suspicious_GEN.F47V0123, Suspicious_GEN.F47V0603
13.04%
NANO AntiVirus
Riskware.Win32.ShouQu.dmnfjx
13.04%
Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F], PE:Malware.Generic/QRS!1.9E2D [F], Adware.NSISmod!1.A1E0
13.04%
F-Prot
W32/Yantai.A.gen, W32/Linkury.C.gen
8.70%
Zillya! Antivirus
Adware.Linkury.Win32.51430, Adware.ShouQuCRTD.Win32.150
8.70%
The domain dl.ke8u.com has been seen to resolve to the following 7 IP addresses.
File downloads found at URLs served by dl.ke8u.com.
Latest 30 of 30 download URLs
The following 32 files have been seen to comunicate with dl.ke8u.com in live environments.
Related Domains