product.mobogenie.com

Beijing Gamease Age Digital Technology Co., Ltd.

Domain Information

The domain product.mobogenie.com registered by Beijing Gamease Age Digital Technology Co., Ltd. was initially registered in November of 2012 through HICHINA ZHICHENG TECHNOLOGY LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Singapore, Singapore within Singapore which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the Asia Pacific (Singapore) region datacenter.
Remove Malware from product.mobogenie.com - Powered by Reason Core Security
Registrar:
MARKMONITOR INC.

Server location:
Singapore, Singapore (SG)

Create date:
Wednesday, November 28, 2012

Expires date:
Tuesday, November 28, 2017

Updated date:
Wednesday, December 24, 2014

ASN:
AS38895 AMAZON-AS-AP Amazon.com Tech Telecom,JP

Root domain:

Scanner detections:
Detections  (85% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.BeijingAmazGameAgeInternetTechnologyCo.a, PUP.Optional.Installer.W, PUP.Optional.Installer.Z, PUP.Optional.Installer.DD, PUP.Optional.Installer.a, PUP.Optional.Installer.Y, PUP.Optional.BeijingAmazGameAgeInternetTechnologyCo.Installer
95.65%

Dr.Web
Win32.Sector.21, Adware.NextLive.2, Adware.Mobogenie.7, Adware.Mobogenie.14
30.43%

Trend Micro House Call
TROJ_GEN.F47V0408, TROJ_GEN.F47V0418, Suspicious_GEN.F47V0626
13.04%

avast!
NSIS:NextLive-A [Adw]
13.04%

ESET NOD32
Win32/Mobogenie
13.04%

Avira AntiVirus
W32/Sality.AT, SPR/ANDR.Mobogen.A.Gen
8.70%

G Data
Win32.Application.Mobogenie
8.70%

IKARUS anti.virus
nbsp;
8.70%

Bkav FE
W32.HfsAdware
8.70%

F-Prot
W32/Sality.gen2
4.35%

F-Secure
Win32.Sality.3
4.35%

Microsoft Security Essentials
Threat.Undefined
4.35%

McAfee
Artemis!9940667030F7
4.35%

McAfee Web Gateway
Artemis!9940667030F7
4.35%

Fortinet FortiGate
Riskware/Mobogenie
4.35%

The domain product.mobogenie.com has been seen to resolve to the following 42 IP addresses.

ec2-52-76-124-71.ap-southeast-1.compute.amazonaws.com
February 3, 2016

ec2-54-254-212-206.ap-southeast-1.compute.amazonaws.com
January 5, 2016

ec2-54-169-196-211.ap-southeast-1.compute.amazonaws.com
November 7, 2015

ec2-54-169-61-248.ap-southeast-1.compute.amazonaws.com
September 10, 2015

ec2-52-74-42-243.ap-southeast-1.compute.amazonaws.com
June 30, 2015

ec2-54-254-240-35.ap-southeast-1.compute.amazonaws.com
June 30, 2015

ec2-54-169-49-106.ap-southeast-1.compute.amazonaws.com
June 30, 2015

ec2-52-74-144-135.ap-southeast-1.compute.amazonaws.com
June 30, 2015

ec2-54-254-235-97.ap-southeast-1.compute.amazonaws.com
May 3, 2015

ec2-54-254-189-184.ap-southeast-1.compute.amazonaws.com
May 3, 2015

ec2-54-255-142-241.ap-southeast-1.compute.amazonaws.com
May 3, 2015

ec2-54-255-163-0.ap-southeast-1.compute.amazonaws.com
May 3, 2015

ec2-54-169-31-185.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-251-175-79.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-251-144-217.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-179-187-34.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-179-137-129.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-169-123-12.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-169-48-68.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-254-168-109.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-255-203-238.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-255-156-117.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-254-136-139.ap-southeast-1.compute.amazonaws.com
December 1, 2014

ec2-54-251-130-173.ap-southeast-1.compute.amazonaws.com
December 1, 2014

ec2-54-179-186-128.ap-southeast-1.compute.amazonaws.com
December 1, 2014

ec2-54-179-186-71.ap-southeast-1.compute.amazonaws.com
December 1, 2014

ec2-54-179-132-13.ap-southeast-1.compute.amazonaws.com
December 1, 2014

ec2-54-179-132-1.ap-southeast-1.compute.amazonaws.com
December 1, 2014

ec2-54-255-205-188.ap-southeast-1.compute.amazonaws.com
December 1, 2014

ec2-54-254-138-74.ap-southeast-1.compute.amazonaws.com
December 1, 2014

 
Showing 30 of 42 IP Addresses

File downloads found at URLs served by product.mobogenie.com.

5 / 68      (false positives)

1 / 68      (PUP)

2 / 68      (PUP)

1 / 68      (PUP)

2 / 68      (PUP)

0 / 68

0 / 68

3 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

2 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

0 / 68

1 / 68      (PUP)

2 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

7 / 68      (PUP)

1 / 68      (PUP)

7 / 68      (PUP)
http://product.mobogenie.com/.../clientDownload.htm?media=21  (7e9197902c9c5f9e0ddf788c4a7ea50f.exe)

9 / 68      (PUP)
http://product.mobogenie.com/.../clientDownload.htm?media=21  (9940667030f7c83be3dd8e38a637233b.exe)

The following 26 files have been seen to comunicate with product.mobogenie.com in live environments.

 
Latest 20 of 74 files

URL:
http://product.mobogenie.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

SSL certificate subject:
CN=*.mobogenie.com, OU=Terms of use at www.verisign.com/rpa (c)05, OU=Product Dept., O="Beijing AmazGame Age Internet Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

SSL certificate issuer:
CN=VeriSign Class 3 Secure Server CA - G3, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Web server:
Tengine

Remove Malware from product.mobogenie.com - Powered by Reason Core Security