install-cdn.cytiweb.net

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain install-cdn.cytiweb.net is registered by proxy through GODADDY.COM, LLC and was originally registered in February of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Akamai Technologies, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
New York, United States (US)

Create date:
Tuesday, February 4, 2014

Expires date:
Saturday, February 4, 2017

Updated date:
Thursday, February 4, 2016

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US

Root domain:

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.CytiWeb.M, PUP.CytiWeb.J, PUP.CytiWeb.I, PUP.CytiWeb.K, PUP.CytiWeb.G, PUP.BHO.CytiWeb.K, PUP.BHO.Yontoo, PUP.Yontoo, PUP.Yontoo.Girafarri.Installer (M), PUP.Yontoo.CytiWeb.Installer (M), PUP.Yontoo.Girafarr.Installer (M), PUP.Yontoo (M)
95.83%

NANO AntiVirus
Trojan.Win32.BPlug.dfsehz, Riskware.Win32.SwiftBrowse.dlbdsd, Trojan.Win32.BPlug.dfogbn, Trojan.Win32.Yontoo.dnkubo
62.50%

Dr.Web
Trojan.BPlug.181, infected with Trojan.BPlug.181, Trojan.Yontoo.476, Trojan.Yontoo.475, Trojan.BPlug.31, Trojan.BPlug.215
62.50%

AVG
Generic, BrowseFox.F, Adware BrowseFox.F, Girafarri, BrowseFox.H, Adware BrowseFox.H, Adware BrowseFox.G
62.50%

Malwarebytes
PUP.Optional.BPlug, PUP.Optional.CytiWeb.A
60.42%

Avira AntiVirus
ADWARE/BrowseFox.Gen, ADWARE/BrowseFox.Gen2
60.42%

Baidu Antivirus
Adware.Win32.BrowseFox
60.42%

G Data
NSIS.Application.BrowseFox, Adware.BrowseFox.BF, Gen:Variant.Adware.BHO.Agent, Adware.BrowseFox.BJ
58.33%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696, Yontoo
56.25%

AhnLab V3 Security
PUP/Win32.SwiftBrowse, Adware/Win32.BrowseFox, PUP/Win32.BrowseFox
56.25%

F-Prot
W32/S-b5aa130f, W32/S-7bed2e86, W32/S-c9f3cc61, W32/S-304afd20, W32/Adware.ALRY (exact, not disinfectable)
56.25%

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen, Malware.QVM06.Gen, Win32/Virus.Adware.80e, HEUR/QVM30.1.Malware.Gen
52.08%

ESET NOD32
Win32/BrowseFox, Win32/BrowseFox (variant), Win32/BrowseFox.C potentially unwanted, Win32/BrowseFox.AE potentially unwanted
45.83%

K7 AntiVirus
Trojan , Unwanted-Program , DoS-Trojan
45.83%

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF, PE:Trojan.Win32.Generic.17D5649F!399860895, PE:Malware.Kranet!6.20B9
43.75%

The domain install-cdn.cytiweb.net has been seen to resolve to the following 40 IP addresses.

a23-15-9-8.deploy.static.akamaitechnologies.com
July 21, 2016

a104-96-220-153.deploy.static.akamaitechnologies.com
July 17, 2016

a104-96-220-178.deploy.static.akamaitechnologies.com
June 28, 2016

a104-96-220-179.deploy.static.akamaitechnologies.com
June 28, 2016

a23-201-103-138.deploy.static.akamaitechnologies.com
May 25, 2016

a23-201-103-144.deploy.static.akamaitechnologies.com
May 25, 2016

a104-96-220-169.deploy.static.akamaitechnologies.com
May 15, 2016

a104-96-220-185.deploy.static.akamaitechnologies.com
May 15, 2016

a23-62-6-131.deploy.static.akamaitechnologies.com
April 14, 2016

a23-62-6-122.deploy.static.akamaitechnologies.com
April 14, 2016

April 13, 2016

April 13, 2016

a23-15-7-122.deploy.static.akamaitechnologies.com
April 6, 2016

a23-62-6-81.deploy.static.akamaitechnologies.com
April 5, 2016

March 4, 2016

March 4, 2016

a72-247-8-122.deploy.akamaitechnologies.com
March 3, 2016

a72-247-8-139.deploy.akamaitechnologies.com
March 3, 2016

a23-15-9-75.deploy.static.akamaitechnologies.com
March 3, 2016

a23-15-9-19.deploy.static.akamaitechnologies.com
March 3, 2016

a72-247-10-11.deploy.akamaitechnologies.com
March 2, 2016

a72-247-10-49.deploy.akamaitechnologies.com
March 2, 2016

February 27, 2016

February 27, 2016

a23-15-7-91.deploy.static.akamaitechnologies.com
February 27, 2016

a23-15-7-138.deploy.static.akamaitechnologies.com
February 27, 2016

a184-51-126-96.deploy.static.akamaitechnologies.com
February 27, 2016

a184-51-126-75.deploy.static.akamaitechnologies.com
February 27, 2016

a23-62-6-59.deploy.static.akamaitechnologies.com
February 23, 2016

a23-62-6-97.deploy.static.akamaitechnologies.com
February 23, 2016

 
Showing 30 of 40 IP Addresses

File downloads found at URLs served by install-cdn.cytiweb.net.

18 / 68    (Adware)

32 / 68    (Adware)

17 / 68    (Adware)

39 / 68    (Adware)

32 / 68    (Adware)

34 / 68    (Adware)

32 / 68    (Adware)

32 / 68    (Adware)

38 / 68    (Adware)

15 / 68    (Adware)

38 / 68    (Adware)

32 / 68    (Adware)

38 / 68    (Adware)

32 / 68    (Adware)

22 / 68    (Adware)

38 / 68    (Adware)

The following 317 files have been seen to comunicate with install-cdn.cytiweb.net in live environments.

 
Latest 20 of 392 files

URL:
http://install-cdn.cytiweb.net/

Web server:
Microsoft-IIS/7.5 (ASP.NET)