spms-storage.spccint.com

Perion Network Ltd.

Domain Information

The domain spms-storage.spccint.com registered by ClientConnect LTD was initially registered in November of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Warsaw, Mazowieckie within Poland which resides on the Akamai Technologies, Inc. network. The domain is associated with the publisher Perion Network Ltd. who is located in Tel Aviv, Israel.
Registrar:
GODADDY.COM, LLC

Server location:
Mazowieckie, Poland (PL)

Create date:
Thursday, November 21, 2013

Expires date:
Sunday, January 1, 2017

Updated date:
Monday, May 4, 2015

ASN:
AS3257 TINET-BACKBONE Tinet SpA,DE

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Baidu Antivirus
PUA.Win32.Conduit.bSearchProtect, PUA.Win32.Conduit.BSearchProtect, Virus.Win32.Neshta.$a
83.33%

Reason Heuristics
PUP.ClientConnect.Q, Win32.Generic
83.33%

ESET NOD32
Win32/Conduit.SearchProtect (variant), Win32/Neshta
66.67%

IKARUS anti.virus
PUA.ClientConnect, Virus.Win32.Neshta
66.67%

Malwarebytes
PUP.Optional.Conduit, PUP.Optional.Conduit.A
66.67%

AVG
Generic, Worm/Delf
66.67%

Trend Micro House Call
Suspicious_GEN.F47V0806, Suspicious_GEN.F47V0813, PE_NESHTA.A
50.00%

McAfee
Artemis!A74E75DBE47B, W32/HLLP.41472.e
33.33%

VIPRE Antivirus
Trojan.Win32.Generic, Virus.Win32.Neshta.a
33.33%

Dr.Web
Adware.Conduit.164, Win32.HLLP.Neshta
33.33%

ESET NOD32
Win32/Conduit.SearchProtect.N potentially unwanted application
16.67%

Bkav FE
W32.NeshtaB.PE
16.67%

MicroWorld eScan
Win32.Neshta.A
16.67%

nProtect
Virus/W32.Neshta
16.67%

Quick Heal
W32.Neshta.C8
16.67%

The domain spms-storage.spccint.com has been seen to resolve to the following 6 IP addresses.

a23-77-94-219.deploy.static.akamaitechnologies.com
July 25, 2016

a104-95-71-77.deploy.static.akamaitechnologies.com
May 18, 2016

a184-50-35-167.deploy.static.akamaitechnologies.com
February 28, 2016

a104-90-22-81.deploy.static.akamaitechnologies.com
February 28, 2016

a172-230-25-198.deploy.static.akamaitechnologies.com
January 3, 2016

a23-8-141-175.deploy.static.akamaitechnologies.com
January 2, 2016

File downloads found at URLs served by spms-storage.spccint.com.

40 / 68    (PUP)

1 / 68      (Adware)

5 / 68      (Adware)

9 / 68      (Adware)

6 / 68      (Adware)

6 / 68      (Adware)

URL:
http://spms-storage.spccint.com/

SSL certificate subject:
CN=*.spccint.com, OU=IT, O=ClientConnect LTD, L=Foster City, S=CA, C=US

SSL certificate issuer:
CN=Verizon Akamai SureServer CA G14-SHA2, OU=Cybertrust, O=Verizon Enterprise Solutions, L=Amsterdam, C=NL

Web server:
Microsoft-IIS/7.5 (ASP.NET)