js2ck.qiwang.safecart.com

REVENUEWIRE INC

Domain Information

SafeCart is RevenueWire's payment processing service for various PC optimization type utilities. Common SafeCart products incldue ParetoLogic, Boost Software, Enigma, and FastAgain PC Booster. The domain js2ck.qiwang.safecart.com registered by REVENUEWIRE INC was initially registered in October of 1997 through ENOM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dreieich, Hessen within Germany which resides on the Incapsula Inc network.
Registrar:
ENOM, INC.

Server location:
Hessen, Germany (DE)

Create date:
Saturday, October 25, 1997

Expires date:
Saturday, October 24, 2015

Updated date:
Monday, November 17, 2014

Root domain:

Scanner detections:
Detections  (71% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.GuangxiNanningQiwangCo.Y
60.00%

McAfee
Artemis!DD0111FE8E46, Artemis!F7B8CEDD529D
40.00%

Trend Micro House Call
TROJ_GEN.R021H07AN15, TROJ_GEN.R04AC0OAT15
40.00%

Kaspersky
Trojan.Win32.Agent
40.00%

Baidu Antivirus
Trojan.Win32.Agent
40.00%

Panda Antivirus
Generic Suspicious
40.00%

ESET NOD32
Win32/PerfectUninstaller (variant)
20.00%

Emsisoft Anti-Malware
Trojan.Win32.PerfectUninstaller.AMN!A2
20.00%

McAfee Web Gateway
Artemis
20.00%

Quick Heal
Trojan.Agen.g8
20.00%

K7 Gateway Antivirus
Riskware
20.00%

K7 AntiVirus
Riskware
20.00%

NANO AntiVirus
Trojan.Win32.Agent.dmhmfh
20.00%

Norman
Suspicious_Gen4.HQHXN
20.00%

avast!
Win32:GenMalicious-DXZ [Trj]
20.00%

The domain js2ck.qiwang.safecart.com has been seen to resolve to the following 3 IP addresses.

199.83.128.38.ip.incapdns.net
May 4, 2015

199.83.128.23.ip.incapdns.net
December 1, 2014

199.83.132.189.ip.incapdns.net
May 1, 2014

File downloads found at URLs served by js2ck.qiwang.safecart.com.

0 / 68
http://js2ck.qiwang.safecart.com/.../download  (perfectuninstaller_setup.exe)

14 / 68    (Malware)
http://js2ck.qiwang.safecart.com/.../download  (perfectuninstaller_setup.exe)

6 / 68      (Malware)
http://js2ck.qiwang.safecart.com/.../download  (perfectuninstaller_setup.exe)

0 / 68
http://js2ck.qiwang.safecart.com/.../download  (perfectuninstaller_setup.exe)

3 / 68      (PUP)
http://js2ck.qiwang.safecart.com/.../download  (perfectuninstaller_setup.exe)

1 / 68      (PUP)
http://js2ck.qiwang.safecart.com/.../download  (perfectuninstaller_setup.exe)

1 / 68      (PUP)
http://js2ck.qiwang.safecart.com/.../download  (perfectuninstaller_setup.exe)