www.akamai-update.biz

WhoisGuard, Inc.  (Proxy Registrant)

Domain Information

The domain www.akamai-update.biz is registered by proxy through ENOM, INC. and was originally registered in March of 2013. Currently this domain has been known to host various forms of malware. The hosted servers are located in San Francisco, California within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
California, United States (US)

Create date:
Wednesday, March 20, 2013

Expires date:
Wednesday, March 19, 2014

Updated date:
Saturday, October 19, 2013

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Gen:Variant.Symmi.28659
100.00%

McAfee
Artemis!14C7180A8C73
100.00%

ESET NOD32
Win32/Injector.ALFU (variant)
100.00%

Trend Micro House Call
TROJ_GEN.F47V0823
100.00%

avast!
Win32:Injector-BJF [Trj]
100.00%

Kaspersky
Trojan-Dropper.Win32.Injector
100.00%

Bitdefender
Gen:Variant.Symmi.28659
100.00%

Sophos
Mal/Generic-S
100.00%

Comodo Security
UnclassifiedMalware
100.00%

F-Secure
Gen:Variant.Symmi.28659
100.00%

Emsisoft Anti-Malware
Gen:Variant.Symmi.28659
100.00%

Microsoft Security Essentials
VirTool:Win32/CeeInject.gen!KC
100.00%

G Data
Gen:Variant.Symmi.28659
100.00%

Fortinet FortiGate
W32/Injector.JGFO!tr
100.00%

Panda Antivirus
Trj/dtcontx.G
100.00%

The domain www.akamai-update.biz has been seen to resolve to the following 2 IP addresses.

(CloudFlare)
November 16, 2013

(CloudFlare)
November 16, 2013

File downloads found at URLs served by www.akamai-update.biz.

25 / 68    (Malware)
http://www.akamai-update.biz/.../c19.exe  (14c7180a8c73578cc8916e15fdf74f39)

URL:
http://www.akamai-update.biz/

Web server:
cloudflare-nginx (PHP/5.4.21)