cdnrep.reimageplus.com

Crossrider Advanced Technologies Ltd.  (via a Proxy Registrant)

Domain Information

The domain cdnrep.reimageplus.com is registered by proxy through GODADDY.COM, LLC and was originally registered in January of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the Highwinds Network Group, Inc. network. The domain is associated with the publisher Crossrider Advanced Technologies Ltd..
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Tuesday, January 3, 2012

Expires date:
Wednesday, January 3, 2018

Updated date:
Monday, January 4, 2016

ASN:
AS20446 HIGHWINDS3 - Highwinds Network Group, Inc.,US

Root domain:

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Reimage (L), Win32.Generic.Reimage.Installer.Meta, PUP.Reimage.Optional.Installer.Meta (L), PUP.Reimage.Optional.Meta (L), PUP.Reimage.ReimageR.Installer.Meta (L), PUP.Reimage.Installer.Meta (L)
96.00%

Dr.Web
riskware program Program.Unwanted.493, riskware program Program.Unwanted.497, riskware program Program.Unwanted.1470
40.00%

Bkav FE
W32.HfsAdware
24.00%

McAfee
Artemis!72CB31555DA5, Artemis!D7830F8B35ED, Artemis!5FC7934C9790, Artemis!B3C7121FD4C9
24.00%

Fortinet FortiGate
Riskware/ReImageRepair
24.00%

Baidu Antivirus
PUA.Win32.ReImageRepair
24.00%

Malwarebytes
PUP.Optional.ReImageRepair.A
16.00%

Trend Micro House Call
Suspicious_GEN.F47V0520, Suspicious_GEN.F47V0528
16.00%

ESET NOD32
Detection.Undefined, Win32/ReImageRepair.F potentially unwanted application
12.00%

ESET NOD32
Win32/ReImageRepair.F potentially unwanted
12.00%

AVG
Generic
12.00%

G Data
Win32.Application.ReImageRepair
8.00%

K7 AntiVirus
Adware
8.00%

VIPRE Antivirus
Trojan.Win32.Generic
8.00%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A
4.00%

The domain cdnrep.reimageplus.com has been seen to resolve to the following IP address.

vip080.ssl.hwcdn.net
October 29, 2015

File downloads found at URLs served by cdnrep.reimageplus.com.

2 / 68      (PUP)
http://cdnrep.reimageplus.com/in/.../ReimageRepair.exe  (055cf647fc2b95de2a5b428682831330)

1 / 68      (PUP)
http://cdnrep.reimageplus.com/in/.../ReimageRepair.exe  (cde1f1236503964230592b6013f2aa79)

2 / 68      (PUP)
http://cdnrep.reimageplus.com/in/.../ReimageRepair.exe  (068da6555315d417179a0d3c86deaf29)

1 / 68      (PUP)
http://cdnrep.reimageplus.com/in/.../ReimageRepair.exe  (cde1f1236503964230592b6013f2aa79)

1 / 68      (PUP)
http://cdnrep.reimageplus.com/ins/.../ReimageRepair.exe  (89a45b96c2ceca28c71532c9cd82c174)

1 / 68      (PUP)
http://cdnrep.reimageplus.com/in/.../ReimageRepair.exe  (cfb958bb68b27e7492381f043550fd98)

1 / 68      (PUP)
http://cdnrep.reimageplus.com/ins/.../ReimageRepair.exe  (03faaebd838edcfd5c3f76cec0f7a23d)

10 / 68    (PUP)
http://cdnrep.reimageplus.com/in/.../ReimageRepair.exe  (cedd8609aa10b477e0cbbc024d540f96)

10 / 68    (PUP)
http://cdnrep.reimageplus.com/ins/.../ReimageRepair.exe  (72cb31555da5996b6dc008f2f6bcbbff)

10 / 68    (PUP)
http://cdnrep.reimageplus.com/ins/.../ReimageRepair.exe  (72cb31555da5996b6dc008f2f6bcbbff)

10 / 68    (PUP)
http://cdnrep.reimageplus.com/ins/.../ReimageRepair.exe  (72cb31555da5996b6dc008f2f6bcbbff)

10 / 68    (PUP)
http://cdnrep.reimageplus.com/ins/.../ReimageRepair.exe  (d7830f8b35ed97a90f47825dd7c522f8)

1 / 68      (Malware)
http://cdnrep.reimageplus.com/.../ReimageExpress.exe  (8f1f2b8c37c744c975b3b965ac741bbe)

2 / 68      (PUP)
http://cdnrep.reimageplus.com/.../ReimagePackage1823.exe  (bfb5f5c07572a3788d901990b68452f5)

11 / 68    (PUP)

11 / 68    (PUP)

11 / 68    (PUP)

The following 137 files have been seen to comunicate with cdnrep.reimageplus.com in live environments.

 
Latest 20 of 165 files