dc694.4shared.com

New IT Solutions Ltd.

Domain Information

The domain dc694.4shared.com registered by New IT Solutions Ltd. was initially registered in January of 2005 through GODADDY.COM, LLC. The domain hosts various software downloads. The hosted servers are located in Fort Worth, Texas within the United States which resides on the DFW Internet Services, Inc. network.
Remove Malware from dc694.4shared.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Texas, United States (US)

Create date:
Tuesday, January 11, 2005

Expires date:
Friday, January 11, 2019

Updated date:
Thursday, January 23, 2014

ASN:
AS40824 WZCOM-US - WZ Communications Inc.

Root domain:

Scanner detections:
Detections  (60% detected)

Scan engine
Details
Detections

McAfee Web Gateway
Artemis!A8563F17A5F3, Artemis!F0DD53D2E97F, BehavesLike.Win32.Downloader.km
60.00%

McAfee
Artemis!A8563F17A5F3, Artemis!F0DD53D2E97F
40.00%

Malwarebytes
PUP.Optional.4Shared, Spyware.Zbot.ED
40.00%

Trend Micro House Call
TROJ_GEN.F47V0831, Suspicious_GEN.F47V0117
40.00%

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant), Win32/Injector.BCYH (variant)
40.00%

Kaspersky
Trojan.Win32.Reconyc, not-a-virus:HEUR:AdWare.Win32.AdLoad
40.00%

Qihoo 360 Security
Win32/Trojan.Multi.daf, Malware.QVM06.Gen
40.00%

Reason Heuristics
PUP.Installer.NewITLimited.U
20.00%

Bkav FE
W32.Clod979.Trojan
20.00%

Dr.Web
Adware.Downware.1417
20.00%

Rising Antivirus
PE:PUF.4Shared!1.9C25
20.00%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
20.00%

herdProtect (fuzzy)
a variant of bd346ed9d56414102e8d6bb446e2135157ba9d28
20.00%

MicroWorld eScan
Gen:Variant.Graftor.140290
20.00%

Bitdefender
Gen:Variant.Graftor.140290
20.00%

The domain dc694.4shared.com has been seen to resolve to the following IP address.

c-e430-u0697-27.webazilla.com
February 7, 2014

File downloads found at URLs served by dc694.4shared.com.

0 / 68

0 / 68
http://dc694.4shared.com/download/.../MAX.EXE  (bf5fddaa58f3a89d1b4e0358f2e4ab4a)

0 / 68

7 / 68      (PUP)

0 / 68

16 / 68    (Malware)
https://dc694.4shared.com/download/KRNPQ8xdce/.../ckCjvNaxWIBVdp  ({395a7992-07ce-7b67-b550-8f92395a7992}.exe)

11 / 68    (Adware)
http://dc694.4shared.com/.../-UtQpTHA  (4shared_desktop_4.0.3.1.exe)

The following file have been seen to comunicate with dc694.4shared.com in live environments.

URL:
http://dc694.4shared.com/

Google Analytics:
UA-306602

Title:
“4shared.com - free file sharing and storage”

SSL certificate subject:
CN=*.4shared.com, OU=Domain Control Validated

SSL certificate issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc."

Web server:
573

Remove Malware from dc694.4shared.com - Powered by Reason Core Security