down2.it376.com

xiao jie

Domain Information

The domain down2.it376.com registered by xiao jie was initially registered in July of 2014 through DOMAIN NAME NETWORK PTY LTD. The hosted servers are located in Hangzhou, Zhejiang within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
DOMAIN NAME NETWORK PTY LTD

Server location:
Zhejiang, China (CN)

Create date:
Thursday, July 17, 2014

Expires date:
Monday, July 17, 2017

Updated date:
Thursday, January 8, 2015

ASN:
AS4134 CHINANET-BACKBONE No.31,Jin-rong Street,CN

Root domain:

Google Safe Browsing:
unwanted

Scan engine
Details
Detections

Reason Heuristics
PUP.Yantai (L), Adware.Downloader.YantaiZh.Installer.Meta (M)
66.67%

Dr.Web
Adware.ShouQu.5, Adware.ShouQu.22
33.33%

ESET NOD32
Win32/Packed.NSISmod.E suspicious application
33.33%

avast!
Win32:Adware-gen [Adw]
33.33%

Emsisoft Anti-Malware
Application.Generic.1657801
33.33%

The domain down2.it376.com has been seen to resolve to the following 4 IP addresses.

July 23, 2016

April 14, 2016

April 14, 2016

April 14, 2016

File downloads found at URLs served by down2.it376.com.

4 / 68      (PUP)

0 / 68
http://down2.it376.com/.../Internet ExpIorer.exe  (fc8dbac402782e164fe944a9d52859bf)

0 / 68

0 / 68
http://down2.it376.com/.../Internet ExpIorer.exe  (35edee76fec7794bafcb42ac8cf8a071)

1 / 68      (PUP)

0 / 68
http://down2.it376.com/.../Internet ExpIorer.exe  (5111474bf77edec2005b4fc13c8aa13a)

1 / 68      (PUP)

URL:
http://down2.it376.com/

SSL certificate subject:
CN=dl2.7r7z.com

SSL certificate issuer:
CN=WoSign CA Free SSL Certificate, O=WoSign CA Limited, C=CN

Web server:
nginx