downlaod.xiaocen.com

Song Li

Domain Information

The domain downlaod.xiaocen.com registered by Song Li was initially registered in November of 2010 through ENAME TECHNOLOGY CO., LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Nanning, Guangxi within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
ENAME TECHNOLOGY CO., LTD.

Server location:
Guangxi, China (CN)

Create date:
Sunday, November 28, 2010

Expires date:
Tuesday, November 28, 2017

Updated date:
Sunday, January 17, 2016

ASN:
AS37963 CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.,Ltd.,CN

Root domain:

Google Safe Browsing:
malware,unwanted

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SHANGHAIFENGHANNETWORKINFORMATIONTECHNOLOGYSTUDIO.Installer (M), PUP.SHANGHAI.Installer (M), PUP.Shanghai.Installer (M), PUP (M)
100.00%

The domain downlaod.xiaocen.com has been seen to resolve to the following 4 IP addresses.

AY140721104848Z
January 30, 2016

January 30, 2016

January 30, 2016

January 30, 2016

File downloads found at URLs served by downlaod.xiaocen.com.

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

0 / 68
http://downlaod.xiaocen.com/.../?cid=1848  (13__3112003__3f7372633d6c6d266c733d6e37396163333737333961__68616f2e3336302e636e__0c74.exe)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

The following 5 files have been seen to comunicate with downlaod.xiaocen.com in live environments.

URL:
http://downlaod.xiaocen.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET)