install-cdn.cdntrolatunt.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain install-cdn.cdntrolatunt.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Akamai Technologies, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Tuesday, March 11, 2014

Expires date:
Friday, March 11, 2016

Updated date:
Monday, March 2, 2015

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.trolatunt.F, PUP.Yontoo (M), PUP.Yontoo.trolatun.Installer (M)
100.00%

MicroWorld eScan
Gen:Variant.Adware.SwiftBrowse.1, Gen:Variant.Adware.BHO.Agent.4
40.00%

McAfee
Artemis!05E5546BF2E9, Artemis!7D9337DE312E
40.00%

SUPERAntiSpyware
Adware.BrowseFox/Variant
40.00%

Trend Micro House Call
Suspici.BBAC4570, TROJ_GE.D1ECB54C
40.00%

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Kranet, not-a-virus:AdWare.Win32.Agent
40.00%

Bitdefender
Gen:Variant.Adware.SwiftBrowse.1, Gen:Variant.Adware.BHO.Agent.4
40.00%

NANO AntiVirus
Trojan.Win32.BPlug.dcnjjv, Riskware.Win32.Agent.crkvek
40.00%

Lavasoft Ad-Aware
Gen:Variant.Adware.SwiftBrowse.1, Gen:Variant.Adware.BHO.Agent.4
40.00%

Sophos
Generic PUA MK, Generic PUA NM
40.00%

F-Secure
Gen:Variant.Adware.SwiftBrowse.1, Gen:Variant.Adware.BHO.Agent.4
40.00%

Dr.Web
Trojan.BPlug.90, Trojan.BPlug.17
40.00%

VIPRE Antivirus
Trojan.Win32.Generic, Yontoo
40.00%

Emsisoft Anti-Malware
Gen:Variant.Adware.SwiftBrowse, Gen:Variant.Adware.BHO.Agent
40.00%

ESET NOD32
Win32/BrowseFox, Win32/BrowseFox (variant)
40.00%

The domain install-cdn.cdntrolatunt.com has been seen to resolve to the following 7 IP addresses.

a104-96-221-58.deploy.static.akamaitechnologies.com
June 28, 2016

a104-96-221-114.deploy.static.akamaitechnologies.com
June 7, 2016

a104-96-221-113.deploy.static.akamaitechnologies.com
June 7, 2016

a104-96-220-219.deploy.static.akamaitechnologies.com
May 21, 2016

a104-96-220-232.deploy.static.akamaitechnologies.com
May 21, 2016

a23-215-132-200.deploy.static.akamaitechnologies.com
February 28, 2016

a23-215-132-193.deploy.static.akamaitechnologies.com
February 28, 2016

File downloads found at URLs served by install-cdn.cdntrolatunt.com.

22 / 68    (Adware)
http://install-cdn.cdntrolatunt.com/setup.exe  (05e5546bf2e99600e6ee79f454325321)

1 / 68      (Adware)
http://install-cdn.cdntrolatunt.com/setup.exe  (0f0e425eca752783a716e23f3674225e)

1 / 68      (Adware)
http://install-cdn.cdntrolatunt.com/setup.exe  (8e98bb7687197c6b9fa2f5c1d1d5e60c)

1 / 68      (Adware)
http://install-cdn.cdntrolatunt.com/setup.exe  (68a1a98eff13bb4d61909490ca3a0036)

22 / 68    (PUP)
http://install-cdn.cdntrolatunt.com/setup.exe  (7d9337de312ede0f4161dc812493af05)

The following 13 files have been seen to comunicate with install-cdn.cdntrolatunt.com in live environments.

URL:
http://install-cdn.cdntrolatunt.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET)