cloud.reimageplus.com

Crossrider Advanced Technologies Ltd.  (via a Proxy Registrant)

Domain Information

The domain cloud.reimageplus.com is registered by proxy through GODADDY.COM, LLC and was originally registered in January of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Los Angeles, California within the United States which resides on the Akamai Technologies, Inc. network. The domain is associated with the publisher Crossrider Advanced Technologies Ltd..
Registrar:
GODADDY.COM, LLC

Server location:
California, United States (US)

Create date:
Tuesday, January 3, 2012

Expires date:
Wednesday, January 3, 2018

Updated date:
Monday, January 4, 2016

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V., US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.ReimageLimited.X, PUP.Optional.ReimageLimited.U, PUP.Optional.ReimageLimited.O, PUP.Optional.ReimageLimited.S
100.00%

Rising Antivirus
NS:Malware.Install!1.9F62, NS:PUF.SilenceInstaller!1.9DDF
57.14%

Trend Micro House Call
TROJ_GEN.F47V1128, Suspicious_GEN.F47V0729
42.86%

Dr.Web
Adware.Plugin.171
42.86%

Qihoo 360 Security
Malware.QVM10.Gen
42.86%

MicroWorld eScan
DeepScan:Generic.Mitglied.22648139
14.29%

Lavasoft Ad-Aware
DeepScan:Generic.Mitglied.22648139
14.29%

F-Secure
DeepScan:Generic.Mitglied.22648139
14.29%

Bkav FE
W32.Clod616.Trojan
14.29%

avast!
Win32:Malware-gen
14.29%

ESET NOD32
Win32/ReImageRepair.C potentially unwanted application
14.29%

The domain cloud.reimageplus.com has been seen to resolve to the following 7 IP addresses.

a96-17-170-25.deploy.akamaitechnologies.com
May 26, 2016

a96-17-170-26.deploy.akamaitechnologies.com
May 26, 2016

a96-17-161-89.deploy.akamaitechnologies.com
April 15, 2016

a96-17-161-98.deploy.akamaitechnologies.com
April 15, 2016

a72-246-64-122.deploy.akamaitechnologies.com
April 13, 2016

a72-246-64-112.deploy.akamaitechnologies.com
April 5, 2016

a72-246-64-121.deploy.akamaitechnologies.com
April 5, 2016

File downloads found at URLs served by cloud.reimageplus.com.

10 / 68    (PUP)

2 / 68      (PUP)
http://cloud.reimageplus.com/ProtectorPackage1014.exe  (9c47cabd579b26ec66e47a3e23699ff0)

4 / 68      (PUP)

2 / 68      (PUP)
http://cloud.reimageplus.com/ProtectorPackage1014x64.exe  (e3793bf301450f70d15311f72ee3939b)

4 / 68      (PUP)

2 / 68      (PUP)
http://cloud.reimageplus.com/ProtectorPackage1014x64a.exe  (1cf8205d76338a8f846036a04caf15fc)

2 / 68      (PUP)
http://cloud.reimageplus.com/.../ReimagePackage1656.exe  (defa5f63054d3af1e346f266b1006ce9)

The following 7 files have been seen to comunicate with cloud.reimageplus.com in live environments.