sp-storage.spccint.com

Perion Network Ltd.

Domain Information

The domain sp-storage.spccint.com registered by ClientConnect LTD was initially registered in November of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Miami, Florida within the United States which resides on the RIPE Network Coordination Centre network. The domain is associated with the publisher Perion Network Ltd. who is located in Tel Aviv, Israel.
Registrar:
GODADDY.COM, LLC

Server location:
Florida, United States (US)

Create date:
Thursday, November 21, 2013

Expires date:
Sunday, January 1, 2017

Updated date:
Monday, May 4, 2015

ASN:
AS16625 AKAMAI-AS - Akamai Technologies, Inc., US

Root domain:

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SearchProtect.Conduit.H, PUP.Installer.ClientConnect.H, PUP.Installer.Conduit, PUP.Conduit, Threat.Conduit.Installer, PUP.Conduit.ClientConnect.Installer (M), PUP.Yontoo.IrrationalNumberApplications.Installer (M), Threat.Win.Reputation.IMP, PUP.Yontoo.SystemsReddick.Installer (M), Adware.Bundle.SLI.Installer.Meta (M), PUP.SoftPulse.YumonSystem.Installer (M), PUP.Somoto.Installer (M), Win32.Generic, PUP.Conduit.ClientCo.Installer (M), PUP.Yontoo.TrafficS.Installer (M), PUP.Air Software.Download.Bundler (M), PUP.Conduit.Bundler (M)
95.65%

Malwarebytes
PUP.Optional.Conduit.A, PUP.Optional.SearchProtect.A
36.96%

Dr.Web
Adware.Conduit.6, Adware.Conduit.82, Adware.Conduit.21, Adware.Conduit.45, Threat.Undefined, Adware.Conduit.298, Adware.Conduit.298, Adware.Conduit.45, Detection.Undefined
36.96%

VIPRE Antivirus
Conduit, Threat.4786236
36.96%

Baidu Antivirus
Trojan.Win32.Conduit.SearchProtect, Adware.Win32.Conduit
36.96%

G Data
Win32.Application.SearchProtect, Win32.Application.Agent.7HPROQ, Win32.Application.SearchProtect.AA@gen
34.78%

Trend Micro House Call
TROJ_GEN.F47V0108, TROJ_GEN.F47V0312, TROJ_GEN.F47V0206, TROJ_GEN.F47V0403, TROJ_GEN.F47V0325, TROJ_GE.3929168B, TROJ_GEN.F47V0311
34.78%

McAfee
Artemis!C0E23C6F8F25, Artemis!9DD712136778, Artemis!B8C3D60D0458, Artemis!ECB79AA0E2CA, Artemis!295E903F5E22, Artemis!DB5034D66A86, Artemis!CE55CEFB9B6E, Artemis!C596AEB18887, Artemis!FCD7CE2B8945
34.78%

K7 AntiVirus
Trojan , Riskware , Unwanted-Program , Adware
34.78%

avast!
Win32:PUP-gen [PUP], Win64:PUP-gen [PUP], Win32:Conduit-B [PUP], Win32:Adware-gen [Adw]
34.78%

Fortinet FortiGate
Riskware/Conduit_SearchProtect, Riskware/Wajam, Adware/Conduit_SearchProtect, Riskware/ClientConnect
34.78%

Sophos
Conduit Search Protect, PUA 'Conduit Search Protect'
32.61%

Panda Antivirus
Adware/Conduit, PUP/Conduit.A, Trj/Genetic.gen, PUP/SearchProtect
30.43%

IKARUS anti.virus
AdWare.SearchProtect, Trojan.SuspectCRC, PUA.ClientConnect
30.43%

ESET NOD32
Win32/Conduit.SearchProtect (variant), Win32/ClientConnect (variant), Win32/ClientConnect.A potentially unwanted (variant)
28.26%

The domain sp-storage.spccint.com has been seen to resolve to the following 42 IP addresses.

a23-49-251-212.deploy.static.akamaitechnologies.com
August 29, 2016

a23-77-94-219.deploy.static.akamaitechnologies.com
July 25, 2016

a23-52-83-118.deploy.static.akamaitechnologies.com
July 21, 2016

a23-45-114-158.deploy.static.akamaitechnologies.com
July 20, 2016

a23-73-147-91.deploy.static.akamaitechnologies.com
July 4, 2016

a23-4-204-145.deploy.static.akamaitechnologies.com
July 3, 2016

a23-2-179-85.deploy.static.akamaitechnologies.com
July 2, 2016

a172-226-88-33.deploy.static.akamaitechnologies.com
June 5, 2016

a172-232-29-186.deploy.static.akamaitechnologies.com
June 5, 2016

a23-77-183-112.deploy.static.akamaitechnologies.com
June 4, 2016

a95-101-8-11.deploy.akamaitechnologies.com
May 25, 2016

a23-202-103-61.deploy.static.akamaitechnologies.com
May 20, 2016

a23-196-119-214.deploy.static.akamaitechnologies.com
May 18, 2016

a104-70-61-164.deploy.static.akamaitechnologies.com
May 16, 2016

a23-56-231-61.deploy.static.akamaitechnologies.com
May 6, 2016

a23-64-104-232.deploy.static.akamaitechnologies.com
April 18, 2016

a23-78-208-11.deploy.static.akamaitechnologies.com
April 15, 2016

a23-56-200-111.deploy.static.akamaitechnologies.com
April 15, 2016

a23-77-169-96.deploy.static.akamaitechnologies.com
April 13, 2016

a23-55-134-246.deploy.static.akamaitechnologies.com
April 13, 2016

a23-37-11-73.deploy.static.akamaitechnologies.com
April 13, 2016

a23-196-0-62.deploy.static.akamaitechnologies.com
April 6, 2016

a23-49-248-224.deploy.static.akamaitechnologies.com
February 23, 2016

a172-231-226-143.deploy.static.akamaitechnologies.com
February 22, 2016

a23-79-219-217.deploy.static.akamaitechnologies.com
February 21, 2016

a184-50-35-167.deploy.static.akamaitechnologies.com
February 9, 2016

a104-90-22-81.deploy.static.akamaitechnologies.com
February 9, 2016

a23-218-42-243.deploy.static.akamaitechnologies.com
February 7, 2016

a104-95-71-77.deploy.static.akamaitechnologies.com
February 3, 2016

a172-232-246-219.deploy.static.akamaitechnologies.com
February 1, 2016

 
Showing 30 of 42 IP Addresses

File downloads found at URLs served by sp-storage.spccint.com.

23 / 68    (Adware)

0 / 68
http://sp-storage.spccint.com/Installer/.../Setup.exe  (34698bb465dee72ed4737b38264263e3)

1 / 68      (PUP)

1 / 68      (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (4df388755f4d3b8db26cd02fd8cc5749)

1 / 68      (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (b84f0cf036a1ba1dab82b3580e304415)

1 / 68      (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (2bbd55aaf9746a74af5534c78c077eb9)

1 / 68      (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (577de3c7c4ed753c730a4fa8c9d0ea71)

1 / 68      (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (52f85b85f3246cd1dada9ef32cffd37d)

1 / 68      (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (setup-c4e6ee81-cef5-45c5-b88a-cd929728148b.exe)

1 / 68      (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (6000f8b32abec0f2f4532fa80694c67b)

1 / 68      (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (08e4574eb6e07a089f70b4d178fe8f6f)

0 / 68
http://sp-storage.spccint.com/Installer/.../Setup.exe  (bdf998722d690d09f2f4a668441fdf9d)

16 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (b516f82f149f230085efcec388e0c1b2)

1 / 68      (PUP)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (83bb9160285668c3789281dd0a0cc398)

0 / 68
http://sp-storage.spccint.com/Installer/.../Setup.exe  (52f7a7b85883ea550c78c8e044aa8098)

18 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (ecb79aa0e2cae61cef8dc46597266a1d)

10 / 68    (Adware)

1 / 68      (Malware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (e1e43a32da61f1b5425d1000460c91eb)

14 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (aac25b7635df540e250fe702cec8a356)

18 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (9dd71213677848031fda91d28d410755)

25 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (2cf6191a1ab0aca2bac604c1e1fc56e0)

18 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (c596aeb188876fd1d979ce53795a9e61)

18 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (ce55cefb9b6e031c1f18458cc9f66cd6)

2 / 68      (PUP)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (007e9bd5bfa3586ff6652384d1494411)

1 / 68      (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (b15e4866a24987edeb480b4bb4236cb8)

18 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (fcd7ce2b89455ae3e0a3550981f1ce4f)

27 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (99110f874d68d0dc1e175d6289e4b1ae)

18 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (ae8ad3e35a4c92627e94b9cf55bbeb00)

18 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (db5034d66a86d86adc49094fd97b1d34)

18 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (42ed3541ffca847f72dd490c56231d55)

 
Latest 30 of 132 download URLs

The following 54 files have been seen to comunicate with sp-storage.spccint.com in live environments.

 
Latest 20 of 104 files

URL:
http://sp-storage.spccint.com/

SSL certificate subject:
CN=*.spccint.com, OU=IT, O=ClientConnect LTD, L=Foster City, S=CA, C=US

SSL certificate issuer:
CN=Verizon Akamai SureServer CA G14-SHA2, OU=Cybertrust, O=Verizon Enterprise Solutions, L=Amsterdam, C=NL

Web server:
Microsoft-IIS/7.5 (ASP.NET)