krvhp.haodown.net

ZhangXiuLi

Domain Information

The domain krvhp.haodown.net registered by ZhangXiuLi was initially registered in April of 2015 through ENAME TECHNOLOGY CO., LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Nanning, Guangxi within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
ENAME TECHNOLOGY CO., LTD.

Server location:
Guangxi, China (CN)

Create date:
Monday, April 13, 2015

Expires date:
Thursday, April 13, 2017

Updated date:
Tuesday, March 22, 2016

ASN:
AS37963 CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.,Ltd.,CN

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SHANGHAI.Installer (M)
100.00%

The domain krvhp.haodown.net has been seen to resolve to the following 4 IP addresses.

April 19, 2016

April 19, 2016

AY140721104848Z
April 19, 2016

April 19, 2016

File downloads found at URLs served by krvhp.haodown.net.

1 / 68      (PUP)
http://krvhp.haodown.net/.../ssbPx  (setup[rsdown.cn]_0535uzz9.exe)

The following 5 files have been seen to comunicate with krvhp.haodown.net in live environments.

URL:
http://krvhp.haodown.net/

Web server:
Microsoft-IIS/7.5 (ASP.NET)