downlaod.vstart.net

Song Li

Domain Information

The domain downlaod.vstart.net registered by Song Li was initially registered in October of 2011 through ENAME TECHNOLOGY CO., LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Nanning, Guangxi within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
ENAME TECHNOLOGY CO., LTD.

Server location:
Guangxi, China (CN)

Create date:
Thursday, October 13, 2011

Expires date:
Friday, October 13, 2017

Updated date:
Sunday, January 17, 2016

ASN:
AS37963 CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.,Ltd.,CN

Root domain:

Google Safe Browsing:
malware,unwanted

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SHANGHAIFENGHANNETWORKINFORMATIONTECHNOLOGYSTUDIO.Installer (M), PUP.SHANGHAI.Installer (M), PUP.Shanghai.Installer (M), PUP (M)
100.00%

Bkav FE
W32.HfsAdware
2.27%

Malwarebytes
PUP.Optional.Softcnapp
2.27%

Zillya! Antivirus
Downloader.Agent.Win32.280102
2.27%

K7 AntiVirus
Unwanted-Program
2.27%

Agnitum Outpost
Riskware.Agent
2.27%

ESET NOD32
Win32/Softcnapp.C.gen potentially unwanted (variant)
2.27%

Clam AntiVirus
Win.Trojan.Generickd-1403
2.27%

Kaspersky
not-a-virus:Downloader.Win32.Agent
2.27%

NANO AntiVirus
Trojan.Win32.Winlock.dqvnat
2.27%

Dr.Web
Trojan.Siggen6.36073
2.27%

VIPRE Antivirus
Trojan-Downloader.Win32.Agent
2.27%

G Data
Win32.Application.Softcnapp
2.27%

Vba32 AntiVirus
Downloader.Agent
2.27%

Fortinet FortiGate
W32/Generic.AC.2003
2.27%

The domain downlaod.vstart.net has been seen to resolve to the following 4 IP addresses.

October 26, 2015

October 26, 2015

October 26, 2015

AY140721104848Z
October 26, 2015

File downloads found at URLs served by downlaod.vstart.net.

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (Malware)

1 / 68      (PUP)

1 / 68      (Malware)

1 / 68      (Malware)
http://downlaod.vstart.net/.../?cid=448  (ispeak2014_0448m9go.exe)

1 / 68      (Malware)

1 / 68      (PUP)

1 / 68      (Malware)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

15 / 68    (PUP)

The following 5 files have been seen to comunicate with downlaod.vstart.net in live environments.

URL:
http://downlaod.vstart.net/

Web server:
Microsoft-IIS/7.5 (ASP.NET)