dl2.it376.com

xiao jie

Domain Information

The domain dl2.it376.com registered by xiao jie was initially registered in July of 2014 through DOMAIN NAME NETWORK PTY LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Huzhou, Zhejiang within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
DOMAIN NAME NETWORK PTY LTD

Server location:
Zhejiang, China (CN)

Create date:
Thursday, July 17, 2014

Expires date:
Monday, July 17, 2017

Updated date:
Thursday, January 8, 2015

ASN:
AS4134 CHINANET-BACKBONE No.31,Jin-rong Street,CN

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (57% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/Baidu.C potentially unwanted, Win32/Packed.NSISmod.A suspicious (variant)
50.00%

Dr.Web
Trojan.KillFiles.28526, riskware program Program.Unwanted.432
50.00%

AVG
Generic
50.00%

Reason Heuristics
PUP.BeijingYuJinChengTechnologyCo.Installer (M), Adware.Downloader.YantaiZh.Installer.Meta (M)
50.00%

Bkav FE
W32.FamVT.YantaiTTc
33.33%

Clam AntiVirus
Win.Trojan.691128
33.33%

NANO AntiVirus
Riskware.Win32.ShouQu.dmnfjx
33.33%

Fortinet FortiGate
W32/Generic.AC.18053
33.33%

McAfee
Artemis!2A4648DE714C
16.67%

avast!
Win32:Malware-gen
16.67%

Bitdefender
Trojan.GenericKD.2697934
16.67%

Emsisoft Anti-Malware
Trojan.GenericKD.2697934
16.67%

Baidu Antivirus
Hacktool.Win32.NSISmod
16.67%

K7 AntiVirus
Unwanted-Program
16.67%

The domain dl2.it376.com has been seen to resolve to the following 5 IP addresses.

August 23, 2016

October 13, 2015

October 13, 2015

October 13, 2015

October 13, 2015

File downloads found at URLs served by dl2.it376.com.

1 / 68      (PUP)

13 / 68    (PUP)

1 / 68      (PUP)

0 / 68

3 / 68      (inconclusive)

1 / 68      (inconclusive)
https://dl2.it376.com/down.php?sid=389  (5590b2ba_1202000051.exe)

7 / 68      (PUP)

URL:
http://dl2.it376.com/

Title:
“dl”

SSL certificate subject:
CN=dl2.7r7z.com

SSL certificate issuer:
CN=WoSign CA Free SSL Certificate, O=WoSign CA Limited, C=CN

Web server:
nginx