Shanghai Dragon Habitat Network Information Technology Co., Ltd.

Publisher Information

Shanghai Dragon Habitat Network Information Technology Co., Ltd. is a software publisher located in Shanghai, China*. The publisher primarily developes software that can be classified as adware.
Authority:
WoSign eCommerce Services Limited

Valid from:
8/28/2012 2:03:24 AM

Valid to:
8/30/2013 7:41:29 AM

Subject:
E=shxiaohei@vip.qq.com, CN="Shanghai Dragon Habitat Network Information Technology Co., Ltd.", O="Shanghai Dragon Habitat Network Information Technology Co., Ltd.", L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign eCommerce Services Limited, C=CN

Serial number:
060e3cd0f5c7ee

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ShanghaiDragonHabitatNetworkInformationTechnologyCo.J, PUP.ShanghaiDragonHabitatNetworkInformationTechnologyCo.Q, PUP.Installer.ShanghaiDragonHabitatNetworkInformationTechnologyCo.L, PUP.ShanghaiDragonHabitatNetworkInformationTechnologyCo.K, PUP.ShanghaiDragonHabitatNetworkInformationTechnologyCo (M), PUP.ShanghaiDragonHabitatNetworkInformationTechnologyCo.Installer (M)
100.00%

McAfee
Artemis!74529155CCF6, Artemis!13A0F573E204
13.33%

Trend Micro House Call
TROJ_GEN.R0CBH0AJE13, TROJ_GEN.R0CBH08HN13
13.33%

avast!
NSIS:Adware-KI [Adw]
13.33%

ViRobot
Trojan.Win32.S.Downloader.3878272, Trojan.Win32.S.Downloader.1924984
13.33%

McAfee Web Gateway
Artemis!74529155CCF6, Heuristic.BehavesLike.Win32.Suspicious-PKR.S
13.33%

AhnLab V3 Security
Trojan/Win32.Downloader
13.33%

Norman
Suspicious_Gen4.ESOLK
6.67%

Sophos
Address Tool Bar
6.67%

Avira AntiVirus
TR/Dropper.Gen
6.67%

1 / 68      (PUP)
gswb.ime.bak0 (by www.guangsu.cn)  (ef1413d492f385e02b0fad948b33f168)

1 / 68      (PUP)
gswb.ime.bak0 (by www.guangsu.cn)  (ad0bc63cb8868275fd19314a6075f879)

1 / 68      (PUP)
gswb.ime.bak (by www.guangsu.cn)  (3f458d3466943d1469f8475daf27559c)

1 / 68      (PUP)
gswb.ime.bak (by www.guangsu.cn)  (605e01f40bb5ed54b18cbb617141ed8a)

1 / 68      (PUP)
soft_sp.exe (by www.guangsu.cn)  (38ee256266095be86a01b936353adbd7)

1 / 68      (PUP)
gswb.ime (by www.guangsu.cn)  (af37141d3a9aeb8427b0eca45ca29d84)

1 / 68      (PUP)
gswb.ime (by www.guangsu.cn)  (9e936fe1f740bdc67ca0db5e5d993ce2)

1 / 68      (PUP)
guangsu_gou.exe  (42de5c9fd5e578024555eb68a42df79d)

1 / 68      (PUP)
Resource.dll (by www.guangsu.cn)  (24deb2656f744f496974123d3cdd890b)

1 / 68      (PUP)
Mutual.exe (by www.guangsu.cn)  (647438e50fb8bfc29cb6d9470b26242a)

1 / 68      (PUP)
gswb.bak.ime (by www.guangsu.cn)  (6eb0d91e2666728cc14446555a231345)

1 / 68      (PUP)
setup_sp010.exe  (791ab7c279b488a2731be6500b887e50)

1 / 68      (PUP)
uninst1373079012.exe (by www.guangsu.cn)  (6966678f4d64903d0c77f379e21900fd)

12 / 68    (PUP)
setup_027.exe  (13a0f573e204643a515102efa65b1904)

12 / 68    (PUP)
setup_369.exe  (74529155ccf6f05d88a538d772a35f77)

Downloads URLs for files signed by Shanghai Dragon Habitat Network Information Technology Co., Ltd..

12 / 68    (PUP)
http://vip.dns-vip.net/.../setup_027.exe  (13a0f573e204643a515102efa65b1904)

12 / 68    (PUP)
http://vip.dns-vip.net/.../setup_023.exe  (74529155ccf6f05d88a538d772a35f77)

12 / 68    (PUP)
http://vip.dns-vip.net/.../setup_364.exe  (74529155ccf6f05d88a538d772a35f77)

12 / 68    (PUP)
http://vip.dns-vip.net/.../setup_369.exe  (74529155ccf6f05d88a538d772a35f77)

The following websites host and distribute files published by Shanghai Dragon Habitat Network Information Technology Co., Ltd..

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Shanghai Dragon Habitat Network Information Technology Co., Ltd. by WoSign eCommerce Services Limited on August 28, 2012 with the serial number '060e3cd0f5c7ee'.