dl3.jijivod.com

Whois Privacy Protection Service, Inc.  (Proxy Registrant)

Domain Information

The domain dl3.jijivod.com is registered by proxy through NAME.COM, INC. and was originally registered in April of 2014. Currently this domain has been known to host various forms of malware. The hosted servers are located in Anshan, Liaoning within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
NAME.COM, INC.

Server location:
Liaoning, China (CN)

Create date:
Wednesday, April 23, 2014

Expires date:
Sunday, April 23, 2017

Updated date:
Friday, April 1, 2016

ASN:
AS4837 CHINA169-BACKBONE CNCGROUP China169 Backbone,CN

Root domain:

Scanner detections:
Malware distribution  (75% detected)

Scan engine
Details
Detections

Vba32 AntiVirus
Backdoor.DarkKomet, suspected of Trojan.Downloader.gen.h
100.00%

AVG
upack, ZTTService
100.00%

Dr.Web
Trojan.Siggen6.22491
75.00%

McAfee
Artemis!3BC53CA2D333, Artemis!8DC5503630D8, Artemis!66E4042B77E1
75.00%

K7 AntiVirus
Riskware
50.00%

Trend Micro House Call
Suspicious_GEN.F47V0211, Suspicious_GEN.F47V0310
50.00%

VIPRE Antivirus
Trojan.Win32.Generic
50.00%

Clam AntiVirus
Win.Trojan.Ramnit-6503
25.00%

The domain dl3.jijivod.com has been seen to resolve to the following IP address.

January 5, 2016

File downloads found at URLs served by dl3.jijivod.com.

7 / 68      (Malware)
http://dl3.jijivod.com/JJPlayersetup_jjvod.exe  (3bc53ca2d33385bc5f353c8227b4ca67)

7 / 68      (Malware)
http://dl3.jijivod.com/JJPlayersetup_jjvod.exe  (jjplayer_2.8.0.1_setup_jjvod.1425882818.exe)

5 / 68      (Malware)
http://dl3.jijivod.com/JJPlayersetup_jjvod.exe  (66e4042b77e1b952cb22dc244c865da8)

2 / 68
http://dl3.jijivod.com/JJPlayersetup_jjvod.exe  (0030fcecbaba183eb5e261e9953c88ae)

URL:
http://dl3.jijivod.com/

Web server:
Microsoft-IIS/7.5