www.po414.net

xianlin xie

Domain Information

The domain www.po414.net registered by xianlin xie was initially registered in October of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the SoftLayer Technologies Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Texas, United States (US)

Create date:
Thursday, October 24, 2013

Expires date:
Wednesday, October 24, 2018

Updated date:
Friday, December 19, 2014

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.SkyTech.A
100.00%

Reason Heuristics
PUP.FuYu.R, PUP.SkytouchTechnologyCoLimited.Q, PUP.SkytouchTechnologyCoLimited.O
100.00%

ESET NOD32
Win32/ELEX.AF (variant)
75.00%

Baidu Antivirus
Adware.Win32.ELEX
75.00%

Agnitum Outpost
Riskware.Agent
75.00%

Dr.Web
Adware.Mutabaha.50, Adware.Mutabaha.53
75.00%

McAfee
Artemis!E371C455F13C
50.00%

VIPRE Antivirus
Trojan.Win32.Generic
50.00%

Trend Micro House Call
TROJ_GEN.F47V0422
50.00%

G Data
Win32.Application.SubTab
50.00%

Fortinet FortiGate
Riskware/Elex
50.00%

AVG
Skytech
50.00%

Rising Antivirus
PE:Worm.Rebhip!1.64F0
25.00%

herdProtect (fuzzy)
a variant of 6ae3769a98696a8f825f43e3d047587e4e7f0551
25.00%

The domain www.po414.net has been seen to resolve to the following 2 IP addresses.

173.193.180.132-static.reverse.softlayer.com
February 1, 2016

173.193.180.130-static.reverse.softlayer.com
February 1, 2016

File downloads found at URLs served by www.po414.net.

2 / 68      (Adware)

7 / 68      (Adware)
http://www.po414.net/hpnt/.../lly_webssearches.exe  (fa2bfae9dc072085444a2d57ba0717c5)

12 / 68    (Adware)
http://www.po414.net/hpnt/.../lly_webssearches.exe  (816083d5b5e67c66604b3021c24b4c81)

13 / 68    (Adware)
http://www.po414.net/hpnt/.../lly_sweet-page.exe  (0bf8b284d3c26ff37e133d854de0ac1e)

The following file have been seen to comunicate with www.po414.net in live environments.

URL:
http://www.po414.net/

Google Analytics:
UA-40570956

Title:
“Free Video Player, AVI/MKV/MP4/CD Player, Media Player Download”

Description:
“GoPlayer is a free & powerful video player which can help you enjoy various video files such as Flash, MKV, AVI, MP4 on PC.”

Web server:
nginx