server.mobogenie.com

Beijing Gamease Age Digital Technology Co., Ltd.

Domain Information

The domain server.mobogenie.com registered by Beijing Gamease Age Digital Technology Co., Ltd. was initially registered in November of 2012 through HICHINA ZHICHENG TECHNOLOGY LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Singapore, Singapore within Singapore which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the Asia Pacific (Singapore) region datacenter.
Remove Malware from server.mobogenie.com - Powered by Reason Core Security
Registrar:
MARKMONITOR INC.

Server location:
Singapore, Singapore (SG)

Create date:
Wednesday, November 28, 2012

Expires date:
Tuesday, November 28, 2017

Updated date:
Wednesday, December 24, 2014

ASN:
AS38895 AMAZON-AS-AP Amazon.com Tech Telecom,JP

Root domain:

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.BeijingAmazGameAgeInternetTechnologyCo.X, PUP.Optional.BeijingAmazGameAgeInternetTechnologyCo.L, PUP.Optional.Installer.BeijingAmazGameAgeInternetTechnologyCo.W, PUP.Optional.BeijingAmazGameAgeInternetTechnologyCo.T, PUP.Optional.Installer.W, PUP.Optional.BeijingAmazGameAgeInternetTechnologyCo.a, PUP.Optional.Installer.V, PUP.Optional.BeijingAmazGameAgeInternetTechnologyCo.Installer
91.11%

Dr.Web
Adware.NextLive.2, Trojan.Siggen6.685, Threat.Undefined
53.33%

avast!
NSIS:NextLive-A [Adw], Win32:PUP-gen [PUP], Win32:Mobogenie-J [Adw]
48.89%

ESET NOD32
Win32/NextLive, Win32/Mobogenie, Android/Mobserv (variant), Win32/Mobogenie.B potentially unwanted
46.67%

Trend Micro House Call
TROJ_GEN.F47V0109, TROJ_GEN.F47V0313, TROJ_GE.0ADD1E3E, TROJ_GEN.F47V0203, TROJ_GE.4943E204, ADW_NEXTLIVE, TROJ_GEN.F47V0408, TROJ_GE.45BAB8AA, TROJ_GEN.F47V0418, TROJ_GEN.F47V0414, TROJ_GEN.F47V0318
40.00%

IKARUS anti.virus
Virus.Win32.Heur, Nsis, AndroidOS.Mobo.B, Win32.NextLive, Win32.SuspectCrc, AndroidOS.AdWare.Mobserv, Virus.Win32.Dropper
35.56%

NANO AntiVirus
Trojan.Win32.NextLive.csjhvj, Trojan.Win32.Click.cttoky
26.67%

Fortinet FortiGate
Android/DriveGenie.A!tr, Adware/Agent, Riskware/Mobogenie
24.44%

Rising Antivirus
NS:Malware.Install!1.9F62, PE:Trojan.Win32.Generic.16594EEF!374951663
22.22%

McAfee
Artemis!579FB275EA7B, Artemis!55CB320CF560, Artemis!38F10675DB8B, Artemis!9EEEA3B146EE, Artemis!2D43C6F8BB6C, Artemis!9940667030F7, Artemis!D341AB4667FB
22.22%

McAfee Web Gateway
Artemis!579FB275EA7B, Artemis!55CB320CF560, Artemis!38F10675DB8B, Artemis!9EEEA3B146EE, Artemis!2D43C6F8BB6C, Artemis!9940667030F7
22.22%

G Data
Win32.Application.Mobogenie, Win32.Adware.NextLive
22.22%

Comodo Security
ApplicUnwnt, ApplicUnwnt.Win32.NextLive.~A
20.00%

Vba32 AntiVirus
AdWare.Agent, AdWare.Agent.ahgx
20.00%

VIPRE Antivirus
Adware.Agent, Trojan.AndroidOS.Generic.A
20.00%

The domain server.mobogenie.com has been seen to resolve to the following 77 IP addresses.

ec2-52-76-124-71.ap-southeast-1.compute.amazonaws.com
February 7, 2016

ec2-54-254-212-206.ap-southeast-1.compute.amazonaws.com
December 19, 2015

ec2-54-169-196-211.ap-southeast-1.compute.amazonaws.com
November 9, 2015

ec2-52-74-144-135.ap-southeast-1.compute.amazonaws.com
September 10, 2015

ec2-52-74-42-243.ap-southeast-1.compute.amazonaws.com
September 10, 2015

ec2-54-254-240-35.ap-southeast-1.compute.amazonaws.com
September 10, 2015

ec2-54-169-61-248.ap-southeast-1.compute.amazonaws.com
September 10, 2015

ec2-54-255-163-0.ap-southeast-1.compute.amazonaws.com
May 6, 2015

ec2-54-169-49-106.ap-southeast-1.compute.amazonaws.com
May 6, 2015

ec2-54-255-142-241.ap-southeast-1.compute.amazonaws.com
May 6, 2015

ec2-54-254-189-184.ap-southeast-1.compute.amazonaws.com
May 6, 2015

ec2-54-254-155-171.ap-southeast-1.compute.amazonaws.com
May 6, 2015

ec2-54-254-235-97.ap-southeast-1.compute.amazonaws.com
May 6, 2015

ec2-54-251-130-173.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-179-186-128.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-179-186-71.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-179-132-13.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-179-132-1.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-255-205-188.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-255-203-238.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-255-156-117.ap-southeast-1.compute.amazonaws.com
December 2, 2014

ec2-54-254-189-82.ap-southeast-1.compute.amazonaws.com
November 10, 2014

ec2-54-254-165-189.ap-southeast-1.compute.amazonaws.com
November 10, 2014

ec2-54-179-137-129.ap-southeast-1.compute.amazonaws.com
November 10, 2014

ec2-54-169-123-12.ap-southeast-1.compute.amazonaws.com
November 10, 2014

ec2-54-169-48-68.ap-southeast-1.compute.amazonaws.com
November 10, 2014

ec2-54-169-31-185.ap-southeast-1.compute.amazonaws.com
November 10, 2014

ec2-46-51-219-184.ap-southeast-1.compute.amazonaws.com
November 10, 2014

ec2-54-255-230-249.ap-southeast-1.compute.amazonaws.com
November 10, 2014

ec2-54-169-66-148.ap-southeast-1.compute.amazonaws.com
September 18, 2014

 
Showing 30 of 77 IP Addresses

File downloads found at URLs served by server.mobogenie.com.

1 / 68      (PUP)

2 / 68      (PUP)

6 / 68      (PUP)

3 / 68      (PUP)

1 / 68      (PUP)

24 / 68    (PUP)

21 / 68    (PUP)

3 / 68      (PUP)

5 / 68      (PUP)

23 / 68    (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

22 / 68    (PUP)

4 / 68      (PUP)

2 / 68      (PUP)

4 / 68      (PUP)

3 / 68      (PUP)

1 / 68      (PUP)

24 / 68    (PUP)

10 / 68    (PUP)
http://server.mobogenie.com/.../downloadClient.htm?media=703  (d341ab4667fb635bd92ab74cae3930ee.exe)

1 / 68      (PUP)

The following 67 files have been seen to comunicate with server.mobogenie.com in live environments.

 
Latest 20 of 304 files

URL:
http://server.mobogenie.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

SSL certificate subject:
CN=*.mobogenie.com, OU=Terms of use at www.verisign.com/rpa (c)05, OU=Product Dept., O="Beijing AmazGame Age Internet Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

SSL certificate issuer:
CN=VeriSign Class 3 Secure Server CA - G3, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Web server:
Tengine

Facebook:
Shares:  1

Statistics are for the previous month.

Remove Malware from server.mobogenie.com - Powered by Reason Core Security