up.3c-automation.com.cn

Domain Information

Server location:
Virginia, United States (US)

ASN:
AS2914 NTT-COMMUNICATIONS-2914 - NTT America, Inc.,US

Scanner detections:
Detections  (88% detected)

Scan engine
Details
Detections

Dr.Web
Adware.TopTools.20, Adware.TopTools.26, Win32.HLLP.Neshta
85.71%

ESET NOD32
Win32/Adware.Eszjuxuan.B application, Win32/Neshta.A virus
71.43%

Reason Heuristics
Adware.Eszjuxuan, PUP.TopTools (M), Adware.Toptools.DB (M)
57.14%

Baidu Antivirus
Win32.Adware.Eszjuxuan
28.57%

VIPRE Antivirus
Threat.4276445
14.29%

F-Prot
W32/HLLP.41472
14.29%

avast!
Win32:Apanas [Trj]
14.29%

F-Secure
Win32.Neshta.A
14.29%

McAfee
Virus.W32/HLLP.41472.e
14.29%

Microsoft Security Essentials
Threat.Undefined
14.29%

AVG
Worm/Delf.FF
14.29%

Norman
Win32.Neshta.A
14.29%

MicroWorld eScan
Gen:Variant.Adware.Razy.63718
14.29%

Bitdefender
Gen:Variant.Adware.Razy.63718
14.29%

Arcabit
Trojan.Adware.Razy.DF8E6
14.29%

The domain up.3c-automation.com.cn has been seen to resolve to the following 2 IP addresses.

firewall.systemarts.com
July 2, 2016

205-177-113-34.static.pccwglobal.net
May 25, 2016

File downloads found at URLs served by up.3c-automation.com.cn.

3 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (PUP)

2 / 68      (PUP)
http://up.3c-automation.com.cn/.../game_284zzi.exe  (e5ec1005c5898e197925ec53b225d5ff)

0 / 68
http://up.3c-automation.com.cn/.../game_284xwe.exe  (d8ff75ad010b8c745824d50d64dfb5b7)

12 / 68    (PUP)

3 / 68      (PUP)

10 / 68    (Malware)
http://up.3c-automation.com.cn/.../setup_303d4s.exe  (44bbfecccab7ca3da65291b92e8dbb4d)

3 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (PUP)

2 / 68      (PUP)
http://up.3c-automation.com.cn/.../qvod_246qnj.exe  (0f8d91afa4a7692db29739d445998fe7)

The following 8 files have been seen to comunicate with up.3c-automation.com.cn in live environments.