setup-14b7.kxcdn.com

proinity GmbH

Domain Information

The domain setup-14b7.kxcdn.com registered by proinity GmbH was initially registered in January of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Manassas, Virginia within the United States which resides on the Leaseweb USA, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Wednesday, January 30, 2013

Expires date:
Monday, January 30, 2017

Updated date:
Wednesday, November 19, 2014

ASN:
AS30633 LEASEWEB-US - Leaseweb USA, Inc.,US

Root domain:

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP, PUP.Amonitize.OpenSource.Installer (M), PUP.SOFTSolyushen.Installer (M), PUP.Somoto.Installer (M), PUP.CPUMiner.PromgazstroiProektTOV.Installer (M)
95.83%

Dr.Web
Trojan.BtcMine.709, Trojan.Amonetize.2893, Trojan.BtcMine.726, Trojan.BtcMine.739, Trojan.BtcMine.711, Trojan.BtcMine.725
37.50%

Quick Heal
RiskTool.BitCoinMin.09327, (Suspicious) - DNAScan
37.50%

avast!
Multi:BitCoinMiner-B [PUP], Win32:Amonetize-JS [PUP], Win32:Miner-B [PUP]
33.33%

ESET NOD32
Win64/BitCoinMiner.AT potentially unsafe (variant), Win32/BitCoinMiner.BY potentially unsafe (variant), Win64/BitCoinMiner.AP potentially unsafe (variant)
33.33%

IKARUS anti.virus
Trojan.BitCoinMiner, PUA.BitCoinMiner
33.33%

AVG
Generic, CoinMiner
33.33%

Avira AntiVirus
TR/BitCoinMiner.4626720.2, TR/BitCoinMiner.4628256
29.17%

Fortinet FortiGate
Riskware/BitCoinMiner, Adware/BitCoinMiner
29.17%

Sophos
Bitcoin Miner (PUA), CpuMiner (PUA)
29.17%

K7 AntiVirus
Unwanted-Program
25.00%

VIPRE Antivirus
Trojan.Win32.Generic, RiskTool.Win32.BitCoinMiner (not malicious)
25.00%

Baidu Antivirus
Hacktool.Win32.BitCoinMiner
20.83%

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
20.83%

Kaspersky
not-a-virus:RiskTool.Win64.BitCoinMiner, not-a-virus:HEUR:RiskTool.Win32.BitCoinMiner
20.83%

The domain setup-14b7.kxcdn.com has been seen to resolve to the following 2 IP addresses.

February 8, 2016

hosted-by.Eqserver.com
February 1, 2016

File downloads found at URLs served by setup-14b7.kxcdn.com.

9 / 68      (Adware)

1 / 68      (PUP)
http://setup-14b7.kxcdn.com/setup.exe  (ec97f1ab212cfde0d497373fcaa10de4)

1 / 68      (PUP)

16 / 68    (Adware)
http://setup-14b7.kxcdn.com/setup.exe  (37ccb2c330c70c77673b4cb6a87b576a)

16 / 68    (Adware)

1 / 68      (PUP)

8 / 68      (Adware)

1 / 68      (PUP)
http://setup-14b7.kxcdn.com/setup.exe  (1d53aaa8ff0b097615219a850ca5a051)

3 / 68      (Adware)

1 / 68      (PUP)

1 / 68      (Adware)

14 / 68    (Adware)

14 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://setup-14b7.kxcdn.com/setup.exe  (f13022c191c9d0d2928c84aa591e07a9)

1 / 68      (Adware)
http://setup-14b7.kxcdn.com/setup.exe  (dcd13bec8b2aa65c057898f4b76ba253)

1 / 68      (Adware)
http://setup-14b7.kxcdn.com/setup.exe  (cpuminer-x11-11.exe)

1 / 68      (Malware)
http://setup-14b7.kxcdn.com/setup.exe  (ce767dc0807cc76746df8ffc71a11f0b)

4 / 68      (Adware)
http://setup-14b7.kxcdn.com/setup.exe  (98032dd84624728761a477901e1fe0a2)

1 / 68      (PUP)

1 / 68      (Adware)

1 / 68      (Adware)
http://setup-14b7.kxcdn.com/setup.exe  (bcd6501a6564af6728f4876f1c55a878)

21 / 68    (PUP)

14 / 68    (Adware)

The following 7 files have been seen to comunicate with setup-14b7.kxcdn.com in live environments.

URL:
http://setup-14b7.kxcdn.com/

SSL certificate subject:
CN=*.kxcdn.com, OU=PositiveSSL Wildcard, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
keycdn-engine