cdn.bubbledock.net

Nosibay

Domain Information

The domain cdn.bubbledock.net registered by Nosibay was initially registered in January of 2010 through OVH. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dulles, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
OVH

Server location:
Virginia, United States (US)

Create date:
Friday, January 22, 2010

Expires date:
Sunday, January 22, 2017

Updated date:
Monday, January 18, 2016

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

McAfee
Artemis!DCE50AB19831, Artemis!1625D12A0FA3, Artemis!B80241F8D24A, Artemis!89F8212D6EAB, Artemis!AFE87ED50398, Trojan.Artemis!484039B92DF4
100.00%

Trend Micro House Call
Suspici.E50E09E0, Suspicious_GEN.F47V1222, Suspicious_GEN.F47V0320, Suspicious_GEN.F47V0403, Suspicious_GEN.F47V0217, Suspicious_GEN.F47V0514
100.00%

Dr.Web
Adware.Downware.9155, Adware.Downware.10519, Adware.Downware.10519, Adware.Downware.9155
100.00%

VIPRE Antivirus
BubbleDock, Threat.4791953
100.00%

Reason Heuristics
PUP.Installer.NOSIBAY.Y, PUP.Installer.NOSIBAY.S
83.33%

AVG
Generic
83.33%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
66.67%

Malwarebytes
PUP.Optional.BubbleDock.A, PUP.Optional.Nosibay.A
50.00%

ESET NOD32
Win32/BubbleDock, Win32/BubbleDock.A potentially unwanted
50.00%

Baidu Antivirus
PUA.Win32.BubbleDock
50.00%

Bkav FE
W32.HfsAdware
50.00%

AhnLab V3 Security
PUP/Win32.BubbleDock
33.33%

IKARUS anti.virus
PUA.BubbleDock
33.33%

herdProtect (fuzzy)
a variant of e5f582616edd6afaebba63cf45489ac60cdf855b, a variant of 25bb8f30a453504e14586428beba718818f27324
33.33%

K7 AntiVirus
Trojan , Riskware
33.33%

The domain cdn.bubbledock.net has been seen to resolve to the following 39 IP addresses.

server-52-85-131-106.iad53.r.cloudfront.net
July 17, 2016

server-52-85-131-83.iad53.r.cloudfront.net
July 17, 2016

server-52-85-131-230.iad53.r.cloudfront.net
July 17, 2016

server-52-85-131-207.iad53.r.cloudfront.net
July 17, 2016

server-52-85-131-195.iad53.r.cloudfront.net
July 17, 2016

server-52-85-131-160.iad53.r.cloudfront.net
July 17, 2016

server-52-85-131-156.iad53.r.cloudfront.net
July 17, 2016

server-52-85-131-136.iad53.r.cloudfront.net
July 17, 2016

server-52-85-142-172.iad12.r.cloudfront.net
May 18, 2016

server-52-85-142-169.iad12.r.cloudfront.net
May 18, 2016

server-52-85-142-124.iad12.r.cloudfront.net
May 18, 2016

server-52-85-142-98.iad12.r.cloudfront.net
May 18, 2016

server-52-85-142-35.iad12.r.cloudfront.net
May 18, 2016

server-52-85-142-31.iad12.r.cloudfront.net
May 18, 2016

server-52-85-142-14.iad12.r.cloudfront.net
May 18, 2016

server-52-85-142-186.iad12.r.cloudfront.net
May 18, 2016

server-54-240-160-230.iad12.r.cloudfront.net
February 22, 2016

server-54-240-160-214.iad12.r.cloudfront.net
February 22, 2016

server-54-240-160-190.iad12.r.cloudfront.net
February 22, 2016

server-54-240-160-185.iad12.r.cloudfront.net
February 22, 2016

server-54-240-160-178.iad12.r.cloudfront.net
February 22, 2016

server-54-240-160-161.iad12.r.cloudfront.net
February 22, 2016

server-54-240-160-51.iad12.r.cloudfront.net
February 22, 2016

server-54-240-160-252.iad12.r.cloudfront.net
February 22, 2016

server-54-192-195-10.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-209.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-197.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-120.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-91.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-67.iad53.r.cloudfront.net
February 8, 2016

 
Showing 30 of 39 IP Addresses

File downloads found at URLs served by cdn.bubbledock.net.

11 / 68    (PUP)

9 / 68      (PUP)

10 / 68    (PUP)

6 / 68      (PUP)

16 / 68    (PUP)

The following 27 files have been seen to comunicate with cdn.bubbledock.net in live environments.

 
Latest 20 of 55 files

URL:
http://cdn.bubbledock.net/

Network:
Amazon Cloudfront

Web server:
AmazonS3