dm.dmccint.com

ClientConnect LTD

Domain Information

dmccint.com is the distribution web host for various Perion/Conduit monitization bundles. Typically an adware bundler will connect with the dmccint.com server to request various offers to display to the user (dynamic offer) based on certain properties of the user's PC. dmccint.com will also server a web page with offer details, mostly adware that will be embedded in the ClientConnect installer. The domain dm.dmccint.com registered by ClientConnect LTD was initially registered in November of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in San Mateo, California within the United States which resides on the Conduit USA, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
California, United States (US)

Create date:
Thursday, November 21, 2013

Expires date:
Sunday, January 1, 2017

Updated date:
Tuesday, January 6, 2015

ASN:
AS56473 CONDUIT-NL Conduit Connect B.V.

Root domain:

Scanner detections:
Detections  (97% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Perion.R, PUP.Perion.Q, PUP.Perion.P, PUP.Perion.O, PUP.Perion.h, PUP.ClientConnect.P, PUP.Bundler.Perion, PUP.Perion.Bundler (M), PUP.Perion.Bundler.Conduit (M), PUP.installCore.Internex.Installer (M)
100.00%

VIPRE Antivirus
Conduit
58.33%

ESET NOD32
Win32/Toolbar.Conduit.AE, Win32/ClientConnect (variant), Win32/Toolbar.Conduit.AE (variant)
58.33%

Dr.Web
Adware.Downware.1895
52.78%

Baidu Antivirus
Adware.Win32.Conduit, Trojan.Win32.ClientConnect, PUA.Win32.ClientConnect, Adware.Win32.Perinet, PUA.Win32.Perinet
50.00%

Malwarebytes
PUP.Optional.Conduit.A, PUP.Optional.ClientConnect
38.89%

Trend Micro House Call
Suspicious_GEN.F47V0616, Suspicious_GEN.F47V0612, Suspicious_GEN.F47V0725, Suspicious_GEN.F47V0617, Suspicious_GEN.F47V0730
38.89%

Kaspersky
not-a-virus:WebToolbar.Win32.Perinet
38.89%

IKARUS anti.virus
PUA.ClientConnect, PUA.Toolbar.Conduit
38.89%

McAfee
Artemis!6304F0626823, Artemis!62D47231E41D, Artemis!3C77E79B5E31, Artemis!DD83C95262C3, Artemis!70AE84CA5EDF, Artemis!61C2DA099E9B, Artemis!C8BC08829A82, Artemis!E533693DB465, Artemis!513E2536EF3A, Artemis!BA06D3C85C64, Artemis!792DFE626947, Artemis!082F6E2F4EAC, RDN/Generic PUP.x!chz
36.11%

Panda Antivirus
Trj/Chgt.C, Trj/Chgt.B, Trj/Chgt.F
27.78%

K7 AntiVirus
Trojan , Adware , Unwanted-Program
22.22%

avast!
Win32:Adware-gen [Adw], Win32:Rootkit-gen [Rtk]
22.22%

Fortinet FortiGate
Riskware/Toolbar_Conduit
19.44%

G Data
Win32.Trojan.Agent.78KU6S, Win32.Application.Conduit, NSIS.Adware.Conduit
11.11%

The domain dm.dmccint.com has been seen to resolve to the following IP address.

June 21, 2014

File downloads found at URLs served by dm.dmccint.com.

 
Latest 30 of 347 download URLs

URL:
http://dm.dmccint.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET)