ab48fd632664469589e72405d403cd9a.setuping-onlinedrive.com

Client Connect Ltd.

Domain Information

The domain ab48fd632664469589e72405d403cd9a.setuping-onlinedrive.com registered by Client Connect Ltd. was initially registered in May of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in San Mateo, California within the United States which resides on the Conduit USA, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
California, United States (US)

Create date:
Sunday, May 5, 2013

Expires date:
Sunday, January 1, 2017

Updated date:
Monday, May 4, 2015

ASN:
AS56473 CONDUIT-NL Conduit Connect B.V.

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Conduit.Installer, PUP.Perion.Bundler.Conduit (M), PUP.Perion.Bundler (M)
94.44%

avast!
Win32:Adware-BRM [PUP], Win32:Evo-gen [Susp]
11.11%

Malwarebytes
PUP.Optional.ClientConnect
5.56%

Zillya! Antivirus
Adware.Perinet.Win32.4
5.56%

K7 AntiVirus
Unwanted-Program
5.56%

Agnitum Outpost
PUA.Downware
5.56%

Trend Micro House Call
Suspicious_GEN.F47V0121
5.56%

Kaspersky
not-a-virus:WebToolbar.Win32.Agent
5.56%

Dr.Web
Adware.Conduit.87
5.56%

VIPRE Antivirus
Conduit
5.56%

G Data
Win32.Application.Agent.Q8NHSG
5.56%

McAfee
Artemis!98295F210636
5.56%

Baidu Antivirus
Adware.Win32.Toolbar
5.56%

ESET NOD32
Win32/ClientConnect (variant)
5.56%

AVG
Generic
5.56%

The domain ab48fd632664469589e72405d403cd9a.setuping-onlinedrive.com has been seen to resolve to the following IP address.

January 30, 2016

File downloads found at URLs served by ab48fd632664469589e72405d403cd9a.setuping-onlinedrive.com.

URL:
http://ab48fd632664469589e72405d403cd9a.setuping-onlinedrive.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET)