download-client.com

Wuxi Yilian LLC

Domain Information

The domain download-client.com registered by Wuxi Yilian LLC was initially registered in December of 2012 through BIZCN.COM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Bodis, LLC network.
Registrar:
BIZCN.COM, INC.

Server location:
New York, United States (US)

Create date:
Monday, December 17, 2012

Expires date:
Thursday, December 17, 2015

Updated date:
Wednesday, January 21, 2015

ASN:
AS53665 BODIS-1 - Bodis, LLC,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.FaglaroEnterprisesLimited.R, PUP.FaglaroEnterprisesLimited.Q, PUP.FaglaroEnterprisesLimited.m, Threat.Win.Reputation.IMP
100.00%

McAfee
Artemis!BA6208CB5C33, Artemis!1FBDCF9C1254, Artemis!3DF8716A2273, Artemis!062BDA96A95E, Artemis!077C56205D58, Artemis!EC35E15F5FAE
100.00%

Malwarebytes
PUP.Optional.ExpressFiles.A
100.00%

Trend Micro House Call
TROJ_GEN.F47V1201, TROJ_GEN.F47V1123, TROJ_GEN.F47V1108, TROJ_GEN.F47V1118, TROJ_GEN.F47V1101, TROJ_GEN.F47V1125, TROJ_GEN.F47V1115
100.00%

avast!
Win32:Downloader-TSH [PUP]
100.00%

Sophos
Express Files
100.00%

VIPRE Antivirus
ExpressFiles Installer, Threat.4783941
100.00%

AhnLab V3 Security
PUP/Win32.ExpressFiles
100.00%

ESET NOD32
Win32/ExpressFiles (variant)
90.00%

Bkav FE
W32.Clod935.Trojan, W32.Clodb54.Trojan, W32.Clod217.Trojan, W32.Clod58d.Trojan, W32.Clod5bd.Trojan, W32.Clod4a8.Trojan, W32.Clod697.Trojan, W32.Clod61d.Trojan
90.00%

K7 AntiVirus
Unwanted-Program
80.00%

herdProtect (fuzzy)
a variant of 6818642e61ab31cab135183567c97f430a79d232, a variant of 2b80df6571c45c48ae793fb3a8aca31af677b1e8, a variant of 7a268514cfc9b35c7492a03c6bcc4e6b3d70ec7f
80.00%

AVG
MalSign.Faglaro Enterprises Limited
60.00%

Avira AntiVirus
ADWARE/Adware.Gen2
60.00%

G Data
Win32.Application.ExpressFiles
60.00%

The domain download-client.com has been seen to resolve to the following 3 IP addresses.

January 29, 2015

February 6, 2014

February 6, 2014

File downloads found at URLs served by download-client.com.

13 / 68    (Adware)

25 / 68    (Adware)

12 / 68    (Adware)
http://download-client.com/.../?wmid=98908&uid=339&q=psytrance samples  (hdclone_free_edition_4.3.4_downloader_hu_99433.exe)

14 / 68    (PUP)
http://download-client.com/.../?wmid=99686&uid=311&q=Wilcom Embroidery Studio e1.5 Multi lang .zip  (wilcom_embroidery_studio_e1.5_multi_lang_.zip_downloader_tn_99686.exe)

10 / 68    (Adware)

The following file have been seen to comunicate with download-client.com in live environments.

URL:
http://download-client.com/

Web server:
Microsoft-IIS/7.5