s2.xiguaplayer.com

Whois Privacy Protection Service, Inc.  (Proxy Registrant)

Domain Information

The domain s2.xiguaplayer.com is registered by proxy through NAME.COM, INC. and was originally registered in March of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Zhongshan, Guangdong within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
NAME.COM, INC.

Server location:
Guangdong, China (CN)

Create date:
Saturday, March 22, 2014

Expires date:
Wednesday, March 22, 2017

Updated date:
Sunday, March 8, 2015

ASN:
AS58543 CHINATELECOM-GUANGDONG-IDC Guangdong,CN

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

McAfee
Artemis!E8149DBAF8F7, Artemis!48A83596CF2C, Artemis!8E39BE78CF46, Artemis!A423F430FC7B
100.00%

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
100.00%

Vba32 AntiVirus
SScope.Trojan.PWS.22627
100.00%

ESET NOD32
Win32/FlyStudio.Packed.AD (variant), Win32/FlyStudio.Packed.AD potentially unwanted (variant)
100.00%

AVG
Suining
100.00%

Reason Heuristics
PUP.SuiningQixiAdvertisingMediaCo.N, PUP.SuiningQixiAdvertisingMediaCo.O, PUP.Installer.SuiningQixiAdvertisingMediaCo
100.00%

VIPRE Antivirus
Trojan.Win32.Generic
50.00%

Trend Micro House Call
Suspicious_GEN.F47V1218
25.00%

IKARUS anti.virus
Trojan.Win32.Antavmu
25.00%

The domain s2.xiguaplayer.com has been seen to resolve to the following 2 IP addresses.

May 3, 2015

May 3, 2015

File downloads found at URLs served by s2.xiguaplayer.com.

6 / 68      (PUP)
http://s2.xiguaplayer.com/xigua_Install.exe  (48a83596cf2cff67c0b8aa3eafadb6f4)

9 / 68      (PUP)
http://s2.xiguaplayer.com/xigua_2_12_0_5.exe  (8e39be78cf4661636e6deb350c80243e)

7 / 68      (PUP)
http://s2.xiguaplayer.com/xigua_Install.exe  (a423f430fc7bff64b33f7302a4a7c851)

6 / 68      (PUP)

URL:
http://s2.xiguaplayer.com/

Web server:
nginx/1.4.1