vzapp.iminent.com

SIEN S.A.

Domain Information

The domain vzapp.iminent.com registered by SIEN was initially registered in May of 2006 through GANDI SAS. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Cambridge, Massachusetts within the United States which resides on the Akamai Technologies, Inc. network. The domain is associated with the publisher SIEN S.A. who is located in Paris, France.
Registrar:
GANDI SAS

Server location:
Massachusetts, United States (US)

Create date:
Tuesday, May 23, 2006

Expires date:
Tuesday, May 23, 2017

Updated date:
Friday, January 29, 2016

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.

Root domain:

Scanner detections:
Detections  (91% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SIENSA.P, PUP.Iminent.F, PUP.Installer.SIENSA.N, PUP.SIENSA.N, PUP.Iminent.N, PUP.Iminent.O, PUP.SIENSA.I, Adware.SIENSA.N, PUP.GetNow.SIENSA.N, PUP.Installer.SIENSA.AA, PUP.Sien.Bundler, PUP.Sien.SIENSA.Bundler (M), PUP.Sien.Iminent.Bundler (M), PUP.Iminent.Toolbar.Installer.Meta (M)
86.36%

Dr.Web
Adware.Plugin.75, Adware.Downware.1769, Adware.Plugin.43, Adware.Plugin.96, Adware.BGuard.47, Adware.Plugin.44, Adware.Downware.2713
50.00%

VIPRE Antivirus
Iminent, Threat.4784938, Threat.4721115
45.45%

Malwarebytes
PUP.Optional.Iminent.A
34.09%

Trend Micro House Call
TROJ_GEN.F47V0816, TROJ_GEN.F47V0722, TROJ_GEN.F47V0509, TROJ_GEN.F47V1120, TROJ_GEN.F47V0410, PAK_Generic.001, Suspici.19253A63
29.55%

McAfee
Artemis!35CA8CD652C8, Artemis!7792493EBC16, Artemis!D2AE3D9844FA, Virus.W32/Sality.gen.z
18.18%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A, Threat.Undefined
13.64%

Kaspersky
HEUR:Trojan.Win32.KillFiles, Virus.Win32.Sality
13.64%

Vba32 AntiVirus
BScope.Trojan-Dropper.Injector, suspected of Trojan.Downloader.gen.h
13.64%

avast!
Win32:Malware-gen, Win32:SaliCode, Win32:Sality
13.64%

AVG
Generic, Win32/Sality
13.64%

F-Prot
W32/A-1932c6fe, W32/Sality.gen2, W32/Sality.E.gen
13.64%

ESET NOD32
Win32/Sality.NBA virus
11.36%

Emsisoft Anti-Malware
Win32.Sality
9.09%

SUPERAntiSpyware
Trojan.Agent/Gen-Graftor, Trojan.Agent/Gen-Napolar, Trojan.Agent/Generic
6.82%

The domain vzapp.iminent.com has been seen to resolve to the following 36 IP addresses.

a104-96-221-57.deploy.static.akamaitechnologies.com
July 22, 2016

a104-96-221-91.deploy.static.akamaitechnologies.com
July 21, 2016

a104-96-221-58.deploy.static.akamaitechnologies.com
July 21, 2016

a104-96-220-99.deploy.static.akamaitechnologies.com
May 26, 2016

a104-96-220-144.deploy.static.akamaitechnologies.com
May 16, 2016

a104-96-220-115.deploy.static.akamaitechnologies.com
May 16, 2016

April 15, 2016

April 15, 2016

a23-0-160-90.deploy.static.akamaitechnologies.com
March 4, 2016

a23-15-7-97.deploy.static.akamaitechnologies.com
March 3, 2016

a23-62-62-177.deploy.static.akamaitechnologies.com
February 22, 2016

a23-62-62-175.deploy.static.akamaitechnologies.com
February 22, 2016

a184-28-17-232.deploy.static.akamaitechnologies.com
February 17, 2016

a184-28-17-240.deploy.static.akamaitechnologies.com
February 17, 2016

a23-0-160-48.deploy.static.akamaitechnologies.com
February 9, 2016

a23-0-160-32.deploy.static.akamaitechnologies.com
February 9, 2016

a23-0-160-97.deploy.static.akamaitechnologies.com
February 3, 2016

a23-0-160-88.deploy.static.akamaitechnologies.com
February 3, 2016

a23-15-7-153.deploy.static.akamaitechnologies.com
February 2, 2016

a23-15-7-114.deploy.static.akamaitechnologies.com
February 2, 2016

a23-3-13-193.deploy.static.akamaitechnologies.com
February 1, 2016

a23-62-6-176.deploy.static.akamaitechnologies.com
February 1, 2016

a23-62-6-210.deploy.static.akamaitechnologies.com
February 1, 2016

February 1, 2016

February 1, 2016

January 5, 2016

January 5, 2016

January 3, 2016

January 3, 2016

a23-67-250-88.deploy.static.akamaitechnologies.com
May 2, 2015

 
Showing 30 of 36 IP Addresses

File downloads found at URLs served by vzapp.iminent.com.

1 / 68      (PUP)

9 / 68      (Malware)

12 / 68    (Infected)

1 / 68      (PUP)

7 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

8 / 68      (Infected)

1 / 68      (PUP)
http://vzapp.iminent.com/vz/9F8A06F5-5916-4C2D-BAD9-C46B3800E9B2/.../ibrowser.exe  (17371617851d60ef1a1a377c156eed2d04e737a3d83e4785f79a762db6153075)

2 / 68      (false positives)

14 / 68    (PUP)

The following 241 files have been seen to comunicate with vzapp.iminent.com in live environments.

 
Latest 20 of 266 files

URL:
http://vzapp.iminent.com/

Web server:
Microsoft-IIS/7.5,MCC-PROD19 (ASP.NET)