f1e0a25341874b78b0e8b9f6ecec69be.setuping-onlinedrive.com

Client Connect Ltd.

Domain Information

The domain f1e0a25341874b78b0e8b9f6ecec69be.setuping-onlinedrive.com registered by Client Connect Ltd. was initially registered in May of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in San Mateo, California within the United States which resides on the Conduit USA, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
California, United States (US)

Create date:
Sunday, May 5, 2013

Expires date:
Sunday, January 1, 2017

Updated date:
Monday, May 4, 2015

ASN:
AS56473 CONDUIT-NL Conduit Connect B.V.

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ClientConnect.EE, PUP.Bundler.Perion.Conduit, PUP.Conduit.Installer, PUP.Perion.Bundler.Conduit (M)
100.00%

avast!
Adware-BRM [PUP], Win32:Adware-BRM [PUP]
43.75%

Dr.Web
Adware.Conduit.87
43.75%

VIPRE Antivirus
Threat.4786236, Conduit
43.75%

Kaspersky
not-a-virus:WebToolbar.Win32.Agent
43.75%

K7 AntiVirus
Unwanted-Program
43.75%

NANO AntiVirus
Trojan.Win32.ClientConnect.deinfe
43.75%

AVG
Generic
43.75%

Malwarebytes
PUP.Optional.ClientConnect
37.50%

Trend Micro House Call
Suspici.05DBE0FE, Suspici.6037135B, Suspici.D2131122, Suspici.8C7FCC2E, Suspicious_GEN.F47V1231, Suspicious_GEN.F47V0102
37.50%

ESET NOD32
Win32/ClientConnect.A potentially unwanted application
25.00%

Qihoo 360 Security
Win32/Virus.WebToolbar.8f1, HEUR/QVM30.1.Malware.Gen, HEUR/QVM42.0.Malware.Gen
25.00%

McAfee
Artemis!B9894890787C, Artemis!A4ABBB8EC749, Artemis!9FC0D33FFAF1, Artemis!39566DE5286D
25.00%

ESET NOD32
Win32/ClientConnect (variant)
18.75%

Baidu Antivirus
Adware.Win32.Toolbar
12.50%

The domain f1e0a25341874b78b0e8b9f6ecec69be.setuping-onlinedrive.com has been seen to resolve to the following IP address.

January 3, 2015

File downloads found at URLs served by f1e0a25341874b78b0e8b9f6ecec69be.setuping-onlinedrive.com.

12 / 68    (Adware)

URL:
http://f1e0a25341874b78b0e8b9f6ecec69be.setuping-onlinedrive.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET)