down.jinyuantg.com

panglei

Domain Information

The domain down.jinyuantg.com registered by panglei was initially registered in March of 2014 through HANGZHOU AIMING NETWORK CO.,LTD. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
HANGZHOU AIMING NETWORK CO.,LTD

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Tuesday, March 4, 2014

Expires date:
Wednesday, March 4, 2015

Updated date:
Friday, April 3, 2015

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Dr.Web
Trojan.PWS.Gina.82
100.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
100.00%

Reason Heuristics
PUP.BeijingYuJinChengTechnologyCo.I, PUP.BeijingYuJinChengTechnologyCo.M
100.00%

MicroWorld eScan
Gen:Variant.KillAV.2
50.00%

McAfee
Artemis!CE62AB8BAE7D
50.00%

Trend Micro House Call
TROJ_GEN.F47V0420
50.00%

Bitdefender
Gen:Variant.KillAV.2
50.00%

Lavasoft Ad-Aware
Gen:Variant.KillAV.2
50.00%

F-Secure
Gen:Variant.KillAV.2
50.00%

Emsisoft Anti-Malware
Gen:Variant.KillAV
50.00%

G Data
Gen:Variant.KillAV
50.00%

The domain down.jinyuantg.com has been seen to resolve to the following IP address.

unallocated.barefruit.co.uk
May 4, 2015

File downloads found at URLs served by down.jinyuantg.com.

11 / 68    (Adware)

11 / 68    (Adware)

3 / 68      (Adware)
http://down.jinyuantg.com/.../?????_45_007.exe  (极爽播放器_37_001.exe)

3 / 68      (Adware)
http://down.jinyuantg.com/.../???????_37_001.exe  (极爽播放器_37_001.exe)

The following 230 files have been seen to comunicate with down.jinyuantg.com in live environments.

 
Latest 20 of 230 files

URL:
http://down.jinyuantg.com/

Web server:
nginx/1.0.15