Download
Community
knowledgeBase
» www.appbusi.com
Overview
Analysis
IPs Addresses (15)
Downloads (288)
Network (37)
Website Detail
www.appbusi.com
China Capital Investment Limited
Domain Information
The domain www.appbusi.com registered by China Capital Investment Limited was initially registered in September of 2015 through Moniker Online Services. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform.
Registrant:
China Capital Investment Limited
Registrar:
DOMAIN ORIGINAL, LLC
Server location:
Virginia, United States (US)
Create date:
Saturday, September 19, 2015
Expires date:
Monday, September 19, 2016
Updated date:
Monday, March 7, 2016
ASN:
AS14618 AMAZON-AES - Amazon.com, Inc.
Root domain:
appbusi.com
Whois:
4 appbusi.com records
Analysis
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Performersoft.GiraffeT.Bundler (M), PUP.Performersoft.Installer.Installer.Meta (M), PUP.Performersoft (M), PUP.Performersoft.Installer (M)
100.00%
IPs Addresses
The domain www.appbusi.com has been seen to resolve to the following 15 IP addresses.
192.230.92.93
192.230.92.93.ip.incapdns.net
August 5, 2016
199.83.132.93
199.83.132.93.ip.incapdns.net
June 24, 2016
104.130.124.96
April 2, 2016
208.91.197.197
March 2, 2016
93.191.169.210
November 25, 2015
109.234.109.82
August 11, 2015
54.235.159.97
ec2-54-235-159-97.compute-1.amazonaws.com
March 5, 2015
50.97.49.243
50.97.49.243-static.reverse.softlayer.com
September 27, 2014
50.97.44.131
50.97.44.131-static.reverse.softlayer.com
September 27, 2014
174.37.181.31
174.37.181.31-static.reverse.softlayer.com
September 27, 2014
173.192.190.227
173.192.190.227-static.reverse.softlayer.com
September 27, 2014
173.192.190.226
173.192.190.226-static.reverse.softlayer.com
August 16, 2014
50.97.49.242
50.97.49.242-static.reverse.softlayer.com
August 16, 2014
50.97.44.130
50.97.44.130-static.reverse.softlayer.com
August 16, 2014
174.37.181.30
174.37.181.30-static.reverse.softlayer.com
August 16, 2014
Downloads
File downloads found at URLs served by www.appbusi.com.
1 / 68 (Adware)
http://www.appbusi.com/.../$vcwKQ5A3aw8qoQEo?v=34&cid=4798&tid=Ym89NiZzbGlkPTMxODk4JnN1YmlkPTQ2ODE1OCZzbz0zNiZjaWNtcD0yNjAzMDgmcHViaWQ9NjM2NDgmY2lwaWQ9NzEyMTAwJmNpc2lkPTY2MUE0RDE4QzEyNTcxNDMyMDQ5NTk0MzA5JmNpcmlkPTY2MUE0RDE4QzEyNTcxNDQxMDcxMzA0MzE0JmNpdWlkPS00NDc2MjQ2MTcwNTY5NDM2Mzg2JmNyaWQ9MjIxNDEzOCZleGNpZD0yMiZvc2xpZD0xMzgwOCZtbXQ9MiZjbnRyeT01OA==&pubid=468158&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$psgBVZlsKw4hsjEP?exename=SoftangoDownloader_MpoExplorer11&cid=3706&soft_id=120994&cert=soft
(SoftangoDownloader_MpoExplorer11.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$mdkhQ5A3YENnnyYP?cid=4427&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$nO0sSZA3d1IilDYT?v=40&cid=4301&tid=lax1CNSw9cGmtqCoZRACGNb8uojwxuzWaiILNzUuOS42My4yNDEoATCW67-fBQ..&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$vtkGaZA3Z0c6kQQT?cid=4939&tid=sin1CMjc2KWVqo6CVBACGPuIiqjFxdX6FiIPMTE3LjIxNC4yNDIuMjQyKAEw0erxnwU.&cert=gits
(SpeedAnalysisSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$juQiZJA3d1IinREq?v=40&cid=4301&tid=ams1CKz7jdbihqPEcBACGPXRn6WN87bdJiIOMTk3Ljc3LjIzOS4xODMoATCU3-ifBQ..&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$icoAXZA3ZV40iiMN?v=19&cid=4197&tid=3wJGRhcsczfpqfqgx37zIdHauQWRMAxfBX1PjNWklRBH2w_mTAj0TqJRWKCjVY2YTcSqgVLZzCIavzp3Yy_Fngumex1-El3ZeyCgsH8-9nJ1-WBqpszhOzMM5Sq8s4gmgltik6BrKMIhVm9pBAkmEjgccdl4ngjXONUwpBQ5oAZAn9VopEncWLqHfiLbVFAvCElvDGiEp1I83Hik-mOALSvr-R8jIC-2ZflulWqW3F1dPMQie0IyeZVCNIDni689RphiqYf42qKvi4vuClktzXdyGmk5ZEbMfWgiJhs3ejUx1aur-wZlHlvHZ0EabHnS0gfP01Pqzm8thazzf2fPql3JMf6SDHEWlh5xdNiIT5MKXRI_nzsE75So1kaVO9Qk-zp4uHgeXVdVat34guogUVI-QkcWK9gkED4mIDBgVg&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$mPQLYZA3d1IimjUX?v=40&cid=4301&tid=fra1CMSO5MSF-JOWHxACGIv8jvqY_O7WBCINNDEuMjUwLjIxNy4yNigBMNW8up8F&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$lMk2QZA3d1IilBco?v=40&cid=4301&tid=lax1CPKAn97gw-fgaRACGLnNz8jKl9vjTCINMTczLjIwMC43MS43NCgBMMqtg6AF&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$n88mepA3ZV40ny8X?v=14&cid=4197&tid=RVciSofBaKaMauiMIwTmpK2N9Z7dHoxAyE4oQWlqoU-HirUKr1qgV9s8JU64yGbAqPIjgLKNDhZ0kNaY6hf1tBCToJ8-CayRZdWrrVX42gf6SQJ-72vg9IzPTyEActn3Wx3_luc2Lly0-is_i3_7_vFjKyxNiidgb0NJGhEnacRGBM8R8XTCHkYh5ck-ANVYByHOHC6NNrIUzFFUhXUwXQIBieLfBRzAxPyVJ2zQZmycN554iPg3jErMEZwczhBBQX1ufwP18YWahty7vHRiHIe68VEY9WIMnm3GcZSnzkSWcltxj1bQmUIWUBgQvtUnkPguE9dbTFZBS7--j609216VnR2Zr6yhTCAOz2WM3lw8aULNtzZAfY1XqH9zi_WYb9o0CceLtWFBp7TbzHamRL-QCuoK29pmWec&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$md0PdZA3d1IinSsd?v=40&cid=4301&tid=sin1CPfihIaa2I-jbxACGOy3lpra3frVXiIMOTEuNzIuMTAyLjI2KAEwlbTYnwU.&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/download3/.../qQE5?v=3&cid=4443&tid=nym1CP-Ww-rB0IunfRACGI_HuJ-ugPWdHiIOMTkxLjIyMC4yMzMuNjYoATCjis-fBQ..&cert=gits
(CodecPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$nsYPS5A3YEIxrC4V?v=27&cid=4455&tid=jyoNV3Nsv2kqUd9zL1x2Cmajo528PJ7VfsnJ0PJxe7zhwVBFdIk5txY-0QWfj-es7mIUgTjwqcSZbIn22e8lF5Qqkx4_U-a_1h14VD_o1KHkXjX2kY5RTNeRTH9qiCwePgQShyhS-WDtbFKpSTBoXeK285kzTRPTCCsldm1-kbUbr_2QVH4BHHVzl2lMv_4pnalFiT8EzUGhjX24YidS09HGBP-DA8plEgUPRkjBsD3MzLUbS5Sif5aPfAQ7Ig-ypf82MjDaeu2MgsINQAOZKhhgxneWLIvGHs6NtqR7oGyobErPlAZ4rU4rQ60iUnG4e3RqzHK4ZWIuFt72P8xebB2oLIM5FHBiUcc8v7hnDZ_J1aUyr9IofW-FIeA_4hlNfcZpEvhbNtkF7PEofoOYGtNzHif03Yq7Aog-ptrVZNuat3zjpaVnffQ964OIrZZerFyjvg&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$j8EqZZA3d1IivgAr?v=40&cid=4301&tid=lax1CKq2taS1n83yLhACGMTAzIaUoIz2PiINMTc5LjgzLjIwLjEyMygBMP-l358F&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$isknSJA3d1IimR0y?v=40&cid=4301&tid=ams1CNXAvMLGsKS9CBACGIey8LT8vMHyKyINMTUxLjIxLjg1LjEwMigBMIC2858F&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$qNcZZZA3d1IitT0T?v=40&cid=4301&tid=fra1CN_WpuWS_-3udxACGJe_q7_oxfmEaSIOMTA5LjEyOS4xNDkuMTkoATDLisifBQ..&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (PUP)
http://www.appbusi.com/.../$uOEhZ5A3d1IivBcM?v=40&cid=4301&tid=fra1COf8_aTtrZz1VxACGND9rszLgpqiKCIMODUuMjQwLjEuMjU0KAEw9sHpnwU.&cert=gits
(videoperformersetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$pOYeZplsKwdgohU4?v=27&cid=3770&clickid=004885450010292495381&cert=gits
(BestCodecsPackSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$hN0tW5A3d1IikjM2?v=40&cid=4301&tid=ams1CLe8067-jI3uNRACGL-OkLugi9z9AyIMNDEuMTQzLjY4LjQ4KAEwmPSDoAU.&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$hN4HaJA3ZV40mCM7?v=14&cid=4197&tid=cyk_H_rWfRx5zRxMUuA_ErY7ALYnC8kGVB5QN_NN0_n2pMkibJs-ToegOuJw_LyK8AU9ghZvJKD7CjqLeKzDHiRuuJDpJlFijEmb9QsmnTKYtDhT0NV6Yzn1p3Ow43yEJph1tR00jGgs2Av1jLoaoaZf0QlzIF1-6CClYDXw0fEdWQEKHe7FHOWVNZ3IHxxUeJbgPzj1nYTiD_pTM5yWIQs7B-TesKPLr_rc1axWmtdIEbu4bTsG8i36tTW8keGAfXfcnIvNCLoG3rFbv4lqcJ85TUm2rW0gfe2LQIvyY04WleY8ICBpOsyUWlyE5KAGmLF5zwV_AmNKvacKqph14BYX5A8wwRAJpB6jmaKBv8dtE4SAzvx5njom17W-_wV7D6Nu_4hsqoL-ja--0sdT2__BmX-YkGE91m83cc1xKu0bq-SR160&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$qtgsX5A3d1Iijjc4?v=40&cid=4301&tid=nym1CMjf48nb3u2PVRACGPiUlO-m3qLAESIOMTYyLjQwLjIzMy4xODQoATCC9eKfBQ..&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$gfkCaZA3ZV40iQ4d?v=19&cid=4197&tid=78gRZ51y7nCsYk2TBWXuVDZ_bU0DE4LUOi2mlHyFo51Xc0ttxufIsgMxFU2DPA5jAaeB29ivZzn3v8wcNRek61n2hA8lCJS6yob5xEsEDDVXS9ScLaY9wVsSPsvkikrrNwV1XLm8sbrpKBPBuBfr35MgHlcMrmDqLswvjyKGTOzNjHXKWycIx-i36KsDnEhd2bUq1pcnm6syddGrWJr0mXrSFEs75voRyZXhSD2buYxNb_QIULv9nD2eWndnTfF5cPl3rFnKBU7x0VXwik1GIAVW6kSjsWTP6ty8Ny57zcaz26uXDZh6Jk8qpS_c0R6JmbmKg8D_l0Zb2UIWL9aqJLe16_RNqIMfWClBHtPcdh1PPmRdX5kjttYiJHdAloHFT761zmT6VHAKFFc5QItVB0Yr_PLVTJ1zh4yQmmZPBZaG8BQDTR60pRvEHizIXbA&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (PUP)
http://www.appbusi.com/.../$hucsZZA3d1Iiohc1?v=40&cid=4301&tid=ams1CILLluCv0c__TBACGJCW2sPf4-XnXSIOMTg4LjgwLjI0MC4xNjUoATDhtYOgBQ..&cert=gits
(videoperformersetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$o9k4VZA3ZV40nR00?v=19&cid=4197&tid=xn90hLyXKyDF0IjVa4fXcklij2f0I8qS8UWONYQkKgLW6L7RF0-agwbQYAElvWgYcMkXZ5QxvJ-IJbegxHlMibGHb-_OIRx79NLrvdhw1DWRm5nWx0z86JiJdNKCx9Vk2gOgLcNUTwYcOaxHR5fhJx-ZvQvrlYUA7NLDuwRMOy1hrdwkXUhtejmz0q-1mpzQSeCueLoxiURqhMUzY3NaxYMXO2oBifXFFi16FvIVqxMkaUMrBxv-RPkfmzatxqgE6fRmN1z5nVakFuc-b0ZxFno2zbUICMqQJlqwLII-LzgwvE48DTIFtAIgQ-84bbOff0UzR4MQxc5QlbS72IhCOSgFqs_AIOTOxqJg-dlH8v15j1LbtMNQ_rca5bIVny16hOYAdzHlCJNOMECcghUxabw&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$ntsFWZA3d1IiuAwi?v=40&cid=4301&tid=sin1CNuL6erHxOjfcBACGPOkl_Kz2ovQGSINMTQuOTkuMTIwLjIxMygBMNPpwp8F&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$icgWa5A3d1IirggJ?v=40&cid=4301&tid=nym1CJXyr_Og8MaKTxACGPCM76yaib2_CyIPMTc5LjE3Ny4xMDkuMTY5KAEwktP3nwU.&mkid=49364226260&mkdm=2&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$uPkoaJA3ZV40ix0w?v=19&cid=4197&tid=yAvI2n2FQ7HDhUBoqYnNlH6yh_9lWKB4ki8TTfagwSEFWitDyX3uomnpzUV9F0SIkuUkh-uXeqXbZdxrokzp2514hwRKTYOCpMsWKklg5FndqXoMnAWGuhziIiRmn9s3pzM8kcKN2yRvfydKfJHQavJdHqBnq-mfdza9yvtoCrINtsWmMW58DPTGXcM3qzkYa9inQS1F7gCRyhyNJmo63GxChK1hU2Oxk_buqJ6x3IT8Y1agfJwbz0tQ1XpdpnViGQ958QIGCWVZGWdLomrJAjeCBFk232PXjTGShz7mzqiYa7rbKyNULxpKD-xLB06QZ3Zt_E0zBtorxkdK1wuT0KvFyOvgPE7V8kJH33YLlBtjD6nESC4e7yR10bvVIIk6SlDvfB7ExuAFIJU1nLTptrKNW7in0UGAqNtITTTfgz5S-A&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$h8osdJA3JkQ7kx0c?cid=4877&cert=gits
(PCPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$gccfQpA3ZV40gTcI?v=19&cid=4197&tid=1mMBmqdyDVeg7kRv3fhBiMDVfRJ5Ap6-IPF3lejyK5tNSJcIFXGXds7qvnwZdNfJJyDn4TxQ0eq3Z7orjnpBrDcc9r85MhcFWXZ6776ekWSPeUJgdrA2nJvy24eN47z78INEQXu1GpltIUXNRjcfH1t1lKmP8snldyo7zuhzuNqtxqHjyfnPRXkL6E414PmfZC_DKLgecZDQR2tMHEbQzWNrgRxe5HB5cCHSq_vev1gIbId7JiMGqVUQVc1F93lnt-KpTGsVlkQxvkxprd5TmKUIxkjQ9dNF0EjBfekZK-Yibeu2Z0kG8PCzNeYaHJCBUFYL48_v8kfuYg-V85hjQwzuVS9yF_N4es2q1Qs5iZo-3Z2dZXb9ZOKD5Xo_NaJVCPQDc-74Ljtafaj9xAeO&cert=gits
(VideoPerformerSetup.exe)
1 / 68 (Adware)
http://www.appbusi.com/.../$lNosZpA3ZV40tBIp?v=19&cid=4197&tid=cUQnV7HKGcAsTBfX4EQBMv7CwhGkA_qCGxTaGejax68bPhVCCFzIhoeL1lG7_1MErlmdRGL_SiAT5RaX_ktQcVEV29f8lFwG3PgfiL50C-Eumg3tFIFO86kUXJ4ZP22yN2G7Xg9IPFtZSocxsuux2iGlHDw0ojnYyIPMxdK11_-VRxa5jSR5-xsg3ZuAkLPrJj1tcaXcLWyVO7WgClAI7MtKqurUNaRR7JR9DdAskvf_a5eCsVYCdoisUM_jzQg1kf-pihKiUcIHzuoWLGM5zQJrrTqLtid6KB2thpEHuSw6A-3Rr2gQzOBcDuYWdS9t9tPAAlSJWH8yIAlyBFDZVmR4AR22VHZN0A0HyAnZ0zR0rSGTHtllZqhe3Sy7FHnioSf42g8mk33TPwYBRCr4YC0fOXU&cert=gits
(VideoPerformerSetup.exe)
Latest 30 of 288 download URLs
Network Communications
The following 37 files have been seen to comunicate with www.appbusi.com in live environments.
TCP »
50.97.49.242
:80
UCBrowser.exe (UC Browser by UCWeb)
TCP »
50.97.49.243
:443
UCBrowser.exe (UC Browser by UCWeb)
TCP »
50.97.49.242
:80
UCBrowser.exe (UC Browser by UCWeb)
TCP »
50.97.49.243
:80
UCBrowser.exe (UC Browser by UCWeb)
TCP »
50.97.49.243
:80
UCBrowser.exe (UC Browser by UCWeb)
TCP »
50.97.49.243
:80
UCBrowser.exe (UC Browser by UCWeb)
TCP »
50.97.49.242
:80
UCBrowser.exe (UC Browser by UCWeb)
TCP »
50.97.49.242
:80
citrio.exe (Citrio by CatalinaGroup)
TCP »
50.97.49.242
:80
UCBrowser.exe (by UCWeb)
TCP »
50.97.49.243
:80
jet.exe (Jet by Performersoft)
TCP »
50.97.49.243
:443
UCBrowser.exe (UC Browser by UCWeb)
TCP »
50.97.49.242
:80
browser.exe (Browser)
TCP »
50.97.49.242
:80
rlvknlg.exe (Relevant-Knowledge by TMRG)
TCP »
50.97.49.243
:443
UCBrowser.exe (UC Browser by UCWeb)
TCP »
50.97.49.243
:80
browser.exe (Browser)
TCP »
50.97.49.243
:443
UCBrowser.exe (UC Browser by UCWeb)
TCP »
50.97.49.242
:80
UCBrowser.exe (UC Browser by UCWeb)
TCP »
50.97.49.242
:80
UCBrowser.exe (by UCWeb)
TCP »
50.97.49.243
:80
UCBrowser.exe (by UCWeb)
TCP »
50.97.49.242
:80
UCBrowser.exe (UC Browser by UCWeb)
Latest 20 of 58 files
Website Details
URL:
http://www.appbusi.com/
Network:
Amazon Web Services (AWS), running an EC2 instance
Web server:
nginx/1.8.1
X