72f5c76b8b504c0c932f4612f98f16a4.download.dmccint.com

ClientConnect LTD

Domain Information

dmccint.com is the distribution web host for various Perion/Conduit monitization bundles. Typically an adware bundler will connect with the dmccint.com server to request various offers to display to the user (dynamic offer) based on certain properties of the user's PC. dmccint.com will also server a web page with offer details, mostly adware that will be embedded in the ClientConnect installer. The domain 72f5c76b8b504c0c932f4612f98f16a4.download.dmccint.com registered by ClientConnect LTD was initially registered in November of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in San Mateo, California within the United States which resides on the Conduit USA, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
California, United States (US)

Create date:
Thursday, November 21, 2013

Expires date:
Sunday, January 01, 2017

Updated date:
Monday, May 04, 2015

ASN:
AS56473 CONDUIT-NL Conduit Connect B.V.

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Perion.L, PUP.Perion.V, PUP.Bundler.Perion
100.00%

Malwarebytes
PUP.Optional.Conduit.A, PUP.Optional.ClientConnect
100.00%

ESET NOD32
Win32/Wajam (variant), Win32/Toolbar.Conduit.AE
100.00%

Dr.Web
Adware.Downware.1895
100.00%

Fortinet FortiGate
Riskware/Wajam, Riskware/Toolbar_Conduit
100.00%

Norman
Obfuscated.K!genr
80.00%

Trend Micro House Call
TROJ_GEN.F47V0206, TROJ_GEN.F47V0321, TROJ_GEN.F47V0303, TROJ_GEN.F47V0428
80.00%

VIPRE Antivirus
Conduit
80.00%

McAfee
Artemis!9D9D767330C7, Artemis!60D468FC1B0B
40.00%

McAfee Web Gateway
Artemis!9D9D767330C7, Artemis!60D468FC1B0B
40.00%

K7 Gateway Antivirus
Unwanted-Program
20.00%

K7 AntiVirus
Unwanted-Program
20.00%

Kaspersky
not-a-virus:WebToolbar.Win32.Perinet
20.00%

NANO AntiVirus
Trojan.Win32.ClientConnect.dgyrqb
20.00%

Antiy Labs AVL
GrayWare[WebToolbar:not-a-virus]/Win32.Perinet.d
20.00%

The domain 72f5c76b8b504c0c932f4612f98f16a4.download.dmccint.com has been seen to resolve to the following IP address.

March 14, 2014

File downloads found at URLs served by 72f5c76b8b504c0c932f4612f98f16a4.download.dmccint.com.

URL:
http://72f5c76b8b504c0c932f4612f98f16a4.download.dmccint.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET)