sp-storage.spccint.com

Perion Network Ltd.

Domain Information

The domain sp-storage.spccint.com registered by ClientConnect LTD was initially registered in November of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Warsaw, Mazowieckie within Poland which resides on the Akamai Technologies, Inc. network. The domain is associated with the publisher Perion Network Ltd. who is located in Tel Aviv, Israel.
Remove Malware from sp-storage.spccint.com - Powered by Reason Core Security
Registrar:
GODADDY.COM, LLC

Server location:
Mazowieckie, Poland (PL)

Create date:
Thursday, November 21, 2013

Expires date:
Sunday, January 01, 2017

Updated date:
Monday, May 04, 2015

ASN:
AS3257 TINET-BACKBONE Tinet SpA,DE

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SearchProtect.Conduit.M, PUP.SearchProtect.Conduit.H, Threat.Conduit.Installer, PUP.Installer.ClientConnect.H, PUP.Conduit, PUP.Installer.Conduit, PUP.Conduit.Installer, PUP.Conduit.ClientConnect.Installer (M)
100.00%

Dr.Web
Adware.Conduit.6, Adware.Conduit.101, Adware.Conduit.45, Adware.Conduit.298, Adware.Conduit.298, Adware.Conduit.45, Adware.Conduit.355
93.18%

Malwarebytes
PUP.Optional.Conduit.A, PUP.Optional.SearchProtect.A
93.18%

VIPRE Antivirus
Conduit, Threat.4786236
93.18%

avast!
Win32:SearchProtect-C [Adw], Win32:PUP-gen [PUP], Win32:Conduit-B [PUP], Win32:Adware-gen [Adw]
88.64%

G Data
Win32.Application.ConduitBrothersoftTB, Adware.BHO.BProtector, Win32.Trojan.Agent.8O9SV1, Win32.Application.SearchProtect
86.36%

Baidu Antivirus
Trojan.Win32.Conduit.SearchProtect, PUA.Win32.ClientConnect, Hacktool.Win32.Downloader, Adware.Win32.Conduit
86.36%

Trend Micro House Call
TROJ_GEN.F47V1014, TROJ_GEN.F47V1128, TROJ_GEN.F47V0108, TROJ_GEN.F47V0305, TROJ_GEN.F47V0323, TROJ_GE.3929168B, Suspicious_GEN.F47V0106
84.09%

McAfee
Artemis!BBDB342CCDEA, Artemis!C0E23C6F8F25, Artemis!B8C3D60D0458, Artemis!B1C76EB29600, Artemis!0D8796B4B106, Artemis!527693813413, Artemis!ADD8A127AC76
84.09%

K7 Gateway Antivirus
Trojan , DoS-Trojan , Unwanted-Program
79.55%

McAfee Web Gateway
Artemis!BBDB342CCDEA, Artemis!C0E23C6F8F25, Artemis!B1C76EB29600, Artemis!0D8796B4B106, Artemis!527693813413
79.55%

K7 AntiVirus
Trojan , Unwanted-Program
77.27%

Sophos
Conduit Search Protect, PUA 'Conduit Search Protect', Conduit Search Protect (PUA)
77.27%

Panda Antivirus
PUP/Conduit.A, Adware/Conduit, Trj/CI.A, PUP/SearchProtect, Trj/Genetic.gen
72.73%

Fortinet FortiGate
Riskware/Conduit_SearchProtect
72.73%

The domain sp-storage.spccint.com has been seen to resolve to the following 17 IP addresses.

a184-50-35-167.deploy.static.akamaitechnologies.com
February 9, 2016

a104-90-22-81.deploy.static.akamaitechnologies.com
February 9, 2016

a23-218-42-243.deploy.static.akamaitechnologies.com
February 7, 2016

a104-95-71-77.deploy.static.akamaitechnologies.com
February 3, 2016

a172-232-246-219.deploy.static.akamaitechnologies.com
February 1, 2016

a23-202-224-11.deploy.static.akamaitechnologies.com
January 5, 2016

a172-231-255-25.deploy.static.akamaitechnologies.com
January 5, 2016

a172-232-178-241.deploy.static.akamaitechnologies.com
January 5, 2016

a172-230-25-198.deploy.static.akamaitechnologies.com
January 4, 2016

a172-232-157-95.deploy.static.akamaitechnologies.com
January 4, 2016

a23-209-68-11.deploy.static.akamaitechnologies.com
January 4, 2016

a184-24-182-248.deploy.static.akamaitechnologies.com
January 4, 2016

a104-90-100-77.deploy.static.akamaitechnologies.com
January 3, 2016

a23-78-249-111.deploy.static.akamaitechnologies.com
January 2, 2016

a23-218-125-117.deploy.static.akamaitechnologies.com
January 2, 2016

a23-8-141-175.deploy.static.akamaitechnologies.com
January 2, 2016

a23-66-215-61.deploy.static.akamaitechnologies.com
April 14, 2014

File downloads found at URLs served by sp-storage.spccint.com.

34 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (bc9673923408abe5ac9afaa75322c10c)

20 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (c4f454b8196c91ba357c5ea97bb30297)

23 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (12fd3fdd30842b7b335c8b3e984bec2b)

28 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (b7a01c0006f328b240b47c652d9501bd)

29 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (a562491c8583fc8e4d80ede6350b1480)

21 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (5ea24772233349782a6916c1808287c2)

27 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (60de1ed5aa4e943481ec5cc18b566e63)

26 / 68    (Adware)

21 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (c016c4c32857daffe6e3eaeb24939592)

22 / 68    (Adware)

16 / 68    (Adware)

9 / 68      (Adware)

30 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (5bbc873c513a7af6a49492c5ada7fef9)

26 / 68    (Adware)

26 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (1ea2b0b02ad69523d85cf69d5aea81d0)

19 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (8998bfb6e9eba543292adae4c3717d06)

21 / 68    (Adware)

21 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (ff01a15a4f4c0a7d260041f478cc4992)

19 / 68    (Adware)

14 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (f3b340f6a5b800062ef214d05ebe7e9c)

23 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (337ee9b3308e4ea266b17bf88244f882)

34 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (2d04f91fb3b4ffff9d5ba584bb5fde37)

17 / 68    (Adware)

26 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

21 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (488ab9e11c6d560ec43141366aadfc4c)

21 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (0d8796b4b1061ce5eb8e4b8853d63b29)

29 / 68    (Adware)
http://sp-storage.spccint.com/Installer/.../Setup.exe  (a267019e68f9e459ac3a0c96f1d98cdb)

21 / 68    (PUP)
http://sp-storage.spccint.com/Installer/.../SPSetup.exe  (54a127c33ed258e922a22143a24942a0)

 
Latest 30 of 45 download URLs

The following 18 files have been seen to comunicate with sp-storage.spccint.com in live environments.

 
Latest 20 of 23 files

URL:
http://sp-storage.spccint.com/

SSL certificate subject:
CN=*.spccint.com, OU=IT, O=ClientConnect LTD, L=Foster City, S=CA, C=US

SSL certificate issuer:
CN=Verizon Akamai SureServer CA G14-SHA2, OU=Cybertrust, O=Verizon Enterprise Solutions, L=Amsterdam, C=NL

Web server:
Microsoft-IIS/7.5 (ASP.NET)

Remove Malware from sp-storage.spccint.com - Powered by Reason Core Security