xiazai.cdren.com

Song Li

Domain Information

The domain xiazai.cdren.com registered by Song Li was initially registered in February of 2005 through ENAME TECHNOLOGY CO., LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Nanning, Guangxi within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
ENAME TECHNOLOGY CO., LTD.

Server location:
Guangxi, China (CN)

Create date:
Thursday, February 3, 2005

Expires date:
Friday, February 3, 2017

Updated date:
Saturday, January 9, 2016

ASN:
AS37963 CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.,Ltd.,CN

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (85% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SHANGHAIFENGHANNETWORKINFORMATIONTECHNOLOGYSTUDIO.Installer (M), PUP.SHANGHAI.Installer (M), PUP (M)
100.00%

Bkav FE
W32.HfsAdware
4.55%

McAfee
Artemis!FD53533C0DE6
4.55%

Malwarebytes
PUP.Optional.Softcnapp
4.55%

VIPRE Antivirus
Trojan-Downloader.Win32.Agent
4.55%

K7 AntiVirus
Unwanted-Program
4.55%

NANO AntiVirus
Trojan.Win32.Winlock.dqvnat
4.55%

ESET NOD32
Win32/Softcnapp.C.gen potentially unwanted (variant)
4.55%

Clam AntiVirus
Win.Trojan.Generickd-1403
4.55%

Kaspersky
not-a-virus:Downloader.Win32.Agent
4.55%

Agnitum Outpost
Riskware.Agent
4.55%

Sophos
Generic PUA ML (PUA)
4.55%

Dr.Web
Trojan.Siggen6.36073
4.55%

Zillya! Antivirus
Downloader.Agent.Win32.281175
4.55%

AhnLab V3 Security
PUP/Win32.Softcnapp
4.55%

The domain xiazai.cdren.com has been seen to resolve to the following 4 IP addresses.

AY140721104848Z
December 4, 2015

December 4, 2015

December 4, 2015

December 4, 2015

File downloads found at URLs served by xiazai.cdren.com.

1 / 68      (Malware)

1 / 68      (Malware)
http://xiazai.cdren.com/.../?cid=255  (setup_0255pomb.exe)

1 / 68      (Malware)
http://xiazai.cdren.com/.../?cid=652  (setup_0652dac7.exe)

0 / 68

1 / 68      (Malware)

1 / 68      (PUP)
http://xiazai.cdren.com/.../?cid=273  (setup_0273xfl4.exe)

1 / 68      (PUP)
http://xiazai.cdren.com/.../?cid=49  (setup_0049rehn.exe)

1 / 68      (PUP)

1 / 68      (PUP)

0 / 68

0 / 68

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://xiazai.cdren.com/.../?cid=998  (setup_0998yjy9.exe)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

0 / 68

1 / 68      (PUP)
http://xiazai.cdren.com/.../?cid=998  (setup_0998k8ir.exe)

1 / 68      (PUP)

20 / 68    (PUP)
http://xiazai.cdren.com/.../?cid=998  (setup_0998tpdh.exe)

The following 5 files have been seen to comunicate with xiazai.cdren.com in live environments.

URL:
http://xiazai.cdren.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET)