5a97c2129d8d4368bcfc7f7b8f3c3752.download.dmccint.com

ClientConnect LTD

Domain Information

dmccint.com is the distribution web host for various Perion/Conduit monitization bundles. Typically an adware bundler will connect with the dmccint.com server to request various offers to display to the user (dynamic offer) based on certain properties of the user's PC. dmccint.com will also server a web page with offer details, mostly adware that will be embedded in the ClientConnect installer. The domain 5a97c2129d8d4368bcfc7f7b8f3c3752.download.dmccint.com registered by ClientConnect LTD was initially registered in November of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in San Mateo, California within the United States which resides on the Conduit USA, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
California, United States (US)

Create date:
Thursday, November 21, 2013

Expires date:
Sunday, January 01, 2017

Updated date:
Tuesday, January 06, 2015

ASN:
AS56473 CONDUIT-NL Conduit Connect B.V.

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

VIPRE Antivirus
Conduit, Threat.4786236
100.00%

Reason Heuristics
PUP.Installer.ClientConnect.Q, PUP.Installer.ClientConnect.L, PUP.ClientConnect.AA
100.00%

AVG
MalSign.Generic
100.00%

McAfee
Artemis!CAE377F98911, Artemis!39DA548D96E4, Artemis!93130B989ACD, Artemis!A65E51EF01AB, Artemis!F39E5147C1E0, Artemis!3CCD7070AF6F
85.71%

Malwarebytes
PUP.Optional.Conduit.A, PUP.Optional.ClientConnect
85.71%

Trend Micro House Call
TROJ_GEN.F47V0323, TROJ_GEN.F47V0504, TROJ_GEN.F47V0505, Suspicious_GEN.F47V0624, Suspicious_GEN.F47V0613, Suspicious_GEN.F47V0822
85.71%

ESET NOD32
Win32/Toolbar.Conduit.AB (variant), Win32/Toolbar.Conduit.AE, Win32/ClientConnect (variant)
85.71%

Dr.Web
Adware.Conduit.43, Adware.Conduit.96, Adware.Conduit.87
71.43%

McAfee Web Gateway
Artemis!CAE377F98911, Artemis!39DA548D96E4, Artemis!93130B989ACD, Artemis!A65E51EF01AB, Artemis!F39E5147C1E0
71.43%

Fortinet FortiGate
Riskware/Toolbar_Conduit, Riskware/ClientConnect
57.14%

avast!
Win32:Adware-BRM [PUP]
57.14%

Baidu Antivirus
Adware.Win32.Conduit, PUA.Win32.ClientConnect, Adware.Win32.Toolbar
42.86%

Agnitum Outpost
PUA.Toolbar.Conduit
28.57%

Norman
Conduit.YH
28.57%

Kaspersky
not-a-virus:WebToolbar.Win32.Agent
28.57%

The domain 5a97c2129d8d4368bcfc7f7b8f3c3752.download.dmccint.com has been seen to resolve to the following IP address.

April 13, 2014

File downloads found at URLs served by 5a97c2129d8d4368bcfc7f7b8f3c3752.download.dmccint.com.

URL:
http://5a97c2129d8d4368bcfc7f7b8f3c3752.download.dmccint.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET)