85b8c6df5acf4b2085b0251667593f92.download.dmccint.com

ClientConnect LTD

Domain Information

dmccint.com is the distribution web host for various Perion/Conduit monitization bundles. Typically an adware bundler will connect with the dmccint.com server to request various offers to display to the user (dynamic offer) based on certain properties of the user's PC. dmccint.com will also server a web page with offer details, mostly adware that will be embedded in the ClientConnect installer. The domain 85b8c6df5acf4b2085b0251667593f92.download.dmccint.com registered by ClientConnect LTD was initially registered in November of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in San Mateo, California within the United States which resides on the Conduit USA, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
California, United States (US)

Create date:
Thursday, November 21, 2013

Expires date:
Sunday, January 1, 2017

Updated date:
Tuesday, January 6, 2015

ASN:
AS56473 CONDUIT-NL Conduit Connect B.V.

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ClientConnect.CC
100.00%

ESET NOD32
Win32/ClientConnect.A potentially unwanted application
100.00%

McAfee
Trojan.Artemis!3AE977CAC29C
100.00%

VIPRE Antivirus
Threat.4786236
100.00%

Dr.Web
Trojan.PWS.Stealer.13174
100.00%

avast!
Adware-BRM [PUP]
100.00%

Kaspersky
not-a-virus:WebToolbar.Win32.Agent
100.00%

Malwarebytes
PUP.Optional.ClientConnect
100.00%

Zillya! Antivirus
Adware.Agent.Win32.9634
100.00%

K7 AntiVirus
Trojan
100.00%

NANO AntiVirus
Riskware.Win32.Conduit.dbqqxi
100.00%

Agnitum Outpost
PUA.Toolbar.Conduit
100.00%

G Data
Win32.Application.Conduit
100.00%

Fortinet FortiGate
Riskware/Toolbar_Conduit
100.00%

AVG
Generic
100.00%

The domain 85b8c6df5acf4b2085b0251667593f92.download.dmccint.com has been seen to resolve to the following IP address.

May 3, 2015

File downloads found at URLs served by 85b8c6df5acf4b2085b0251667593f92.download.dmccint.com.

15 / 68    (Adware)

URL:
http://85b8c6df5acf4b2085b0251667593f92.download.dmccint.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET)