box.cr173.com

Wu hong

Domain Information

The domain box.cr173.com registered by Wu hong was initially registered in April of 2006 through GODADDY.COM, LLC. Currently this domain has been known to host various forms of malware. The hosted servers are located in Jishou, Hunan within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Hunan, China (CN)

Create date:
Wednesday, April 19, 2006

Expires date:
Thursday, April 19, 2018

Updated date:
Wednesday, April 22, 2015

ASN:
AS4134 CHINANET-BACKBONE No.31,Jin-rong Street,CN

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Malware distribution  (80% detected)

Scan engine
Details
Detections

McAfee
Artemis!21927716FA77, Artemis!26CFA25FA642, Artemis!40C4CD0D3445, Artemis!3E91A71626C0, Artemis!7539B72238DE
100.00%

McAfee Web Gateway
Artemis!21927716FA77, Artemis!26CFA25FA642, Artemis!40C4CD0D3445, BehavesLike.Win32.Tool.vc
100.00%

Norman
DLoader.AOCCN
80.00%

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra, Trojan.Win32.Generic!SB.0
80.00%

Antiy Labs AVL
Worm/Win32.Qvod, GrayWare[:not-a-virus]/Win32.StartPage.gen
80.00%

Trend Micro House Call
TROJ_GEN.F47V1129, TROJ_GE.A3A4935F, TROJ_GEN.F47V1105
60.00%

Bkav FE
W32.Clodf22.Trojan, W32.Clodbe7.Trojan, W32.Clodbe1.Trojan
60.00%

Comodo Security
Application.Win32.StartPage.IKS
40.00%

AVG
SHeur4
20.00%

Quick Heal
(Suspicious) - DNAScan
20.00%

Vba32 AntiVirus
BScope.Lipler.045
20.00%

XVirus List
Win32.Detected
20.00%

Clam AntiVirus
Win.Trojan.Clicker-3867
20.00%

IKARUS anti.virus
Trojan-Dropper.Agent
20.00%

The domain box.cr173.com has been seen to resolve to the following 3 IP addresses.

June 29, 2016

December 27, 2013

December 27, 2013

File downloads found at URLs served by box.cr173.com.

6 / 68      (inconclusive)

7 / 68      (PUP)

8 / 68      (Malware)

7 / 68      (Malware)

8 / 68      (Malware)
http://box.cr173.com/.../setup_69538.exe  (40c4cd0d344520e9e626a984415a4769)

7 / 68      (Malware)
http://box.cr173.com/.../xixiaddress_33146.exe  (21927716fa770abb2193390f256e301e)