xiazai.dns-vip.net

Song Li

Domain Information

The domain xiazai.dns-vip.net registered by Song Li was initially registered in September of 2012 through ENAME TECHNOLOGY CO., LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Nanning, Guangxi within China which resides on the Asia Pacific Network Information Centre network.
Registrar:
ENAME TECHNOLOGY CO., LTD.

Server location:
Guangxi, China (CN)

Create date:
Friday, September 14, 2012

Expires date:
Thursday, September 14, 2017

Updated date:
Sunday, January 17, 2016

ASN:
AS37963 CNNIC-ALIBABA-CN-NET-AP Hangzhou Alibaba Advertising Co.,Ltd.,CN

Root domain:

Google Safe Browsing:
malware,unwanted

Scanner detections:
Detections  (71% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SHANGHAIFENGHANNETWORKINFORMATIONTECHNOLOGYSTUDIO.Installer (M), PUP.SHANGHAI.Installer (M), PUP (M)
83.33%

Bkav FE
W32.HfsAdware
16.67%

Quick Heal
TrojanDownloader.NSIS.BeautyC
16.67%

Malwarebytes
PUP.Optional.Softcnapp
16.67%

VIPRE Antivirus
Trojan.Win32.Generic
16.67%

K7 AntiVirus
Unwanted-Program
16.67%

NANO AntiVirus
Trojan.Win32.Winlock.dqvnat
16.67%

ESET NOD32
Win32/Softcnapp.C.gen potentially unwanted (variant)
16.67%

Clam AntiVirus
Win.Trojan.Generickd-1403
16.67%

Agnitum Outpost
Riskware.Agent
16.67%

Dr.Web
Trojan.Siggen6.36073
16.67%

Zillya! Antivirus
Downloader.Agent.Win32.281175
16.67%

Avira AntiVirus
PUA/Softcnapp.Gen
16.67%

AhnLab V3 Security
PUP/Win32.Softcnapp
16.67%

G Data
Win32.Application.Softcnapp
16.67%

The domain xiazai.dns-vip.net has been seen to resolve to the following 4 IP addresses.

December 17, 2015

December 17, 2015

AY140721104848Z
December 17, 2015

December 17, 2015

File downloads found at URLs served by xiazai.dns-vip.net.

1 / 68      (Malware)

1 / 68      (PUP)

1 / 68      (PUP)

2 / 68      (inconclusive)
http://xiazai.dns-vip.net/.../?cid=2065  (IQIYIsetup_qudao@kb048.exe)

0 / 68

1 / 68      (PUP)

17 / 68    (PUP)

The following 5 files have been seen to comunicate with xiazai.dns-vip.net in live environments.

URL:
http://xiazai.dns-vip.net/

Web server:
Microsoft-IIS/7.5 (ASP.NET)