www.mobogenie.com

Beijing Gamease Age Digital Technology Co., Ltd.

Domain Information

The domain www.mobogenie.com registered by Beijing Gamease Age Digital Technology Co., Ltd. was initially registered in November of 2012 through HICHINA ZHICHENG TECHNOLOGY LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Singapore, Singapore within Singapore. The domain uses the Amazon Web Services (AWS) cloud computing platform from the Asia Pacific (Singapore) region datacenter.
Registrar:
MARKMONITOR INC.

Server location:
Singapore, Singapore (SG)

Create date:
Wednesday, November 28, 2012

Expires date:
Tuesday, November 28, 2017

Updated date:
Wednesday, December 24, 2014

ASN:
AS38895 AMAZON-AS-AP Amazon.com Tech Telecom, JP

Root domain:

Scanner detections:
Detections  (67% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.BeijingAmazGameAgeInternetTechnologyCo.W, PUP.Optional.Installer.AA, PUP.Optional.BeijingAmazGameAgeInternetTechnologyCo.W
55.56%

Dr.Web
Adware.NextLive.2, Threat.Undefined, Detection.Undefined
55.56%

avast!
NSIS:NextLive-A [Adw], Mobogenie-J [Adw]
44.44%

ESET NOD32
Win32/Adware.Mobogenie.A application, Detection.Undefined, Win32/Mobogenie.B potentially unwanted application
44.44%

ESET NOD32
Win32/Mobogenie (variant), Win32/Mobogenie.B potentially unwanted
33.33%

NANO AntiVirus
Trojan.Win32.NextLive.csjhvj
22.22%

Trend Micro House Call
ADW_NEXTLIVE, Suspici.F994BFB8
22.22%

IKARUS anti.virus
AdWare.AndroidOS.Mobserv, AndroidOS.AdWare.Mobserv
22.22%

MicroWorld eScan
Adware.NewNextMe.A
11.11%

Malwarebytes
PUP.Optional.NextLive.A
11.11%

VIPRE Antivirus
Trojan.AndroidOS.Generic.A
11.11%

Lavasoft Ad-Aware
Adware.NewNextMe.A
11.11%

Comodo Security
ApplicUnwnt.Win32.NextLive.~A
11.11%

F-Secure
Adware.NewNextMe.A
11.11%

Avira AntiVirus
APPL/NextLive.opea.2
11.11%

The domain www.mobogenie.com has been seen to resolve to the following 14 IP addresses.

ec2-54-251-173-39.ap-southeast-1.compute.amazonaws.com
July 30, 2016

ec2-52-77-66-155.ap-southeast-1.compute.amazonaws.com
July 30, 2016

ec2-52-76-100-35.ap-southeast-1.compute.amazonaws.com
June 30, 2016

ec2-52-74-102-198.ap-southeast-1.compute.amazonaws.com
June 30, 2016

ec2-54-169-73-101.ap-southeast-1.compute.amazonaws.com
May 21, 2016

ec2-52-77-160-220.ap-southeast-1.compute.amazonaws.com
May 21, 2016

ec2-54-169-233-254.ap-southeast-1.compute.amazonaws.com
May 16, 2016

ec2-52-77-108-243.ap-southeast-1.compute.amazonaws.com
May 16, 2016

ec2-52-76-188-14.ap-southeast-1.compute.amazonaws.com
January 3, 2016

ec2-52-76-124-9.ap-southeast-1.compute.amazonaws.com
January 3, 2016

ec2-54-251-160-127.ap-southeast-1.compute.amazonaws.com
April 16, 2014

ec2-54-251-159-108.ap-southeast-1.compute.amazonaws.com
April 16, 2014

February 6, 2014

February 6, 2014

File downloads found at URLs served by www.mobogenie.com.

2 / 68      (PUP)

0 / 68

2 / 68      (PUP)
http://www.mobogenie.com/.../Mobogenie_Setup_server2.exe  (mobogenie_setup_server2_你知道網路上有 90% 的電腦都遭到了間諜軟體感染了嗎?只要你在沒有任何防護的情形下連上網際網路,哪怕只是瀏覽幾張網頁都有可能被間諜軟體所感染。.exe)

20 / 68    (PUP)
http://www.mobogenie.com/.../Mobogenie_Setup_2.1.35_5.exe  (960e7881e119840545772afff0499b6f)

0 / 68

1 / 68      (inconclusive)
http://www.mobogenie.com/.../Mobogenie_Setup_2.1.9_21.exe  (1edc751a849816f0634e30c241e3bebf)

3 / 68      (PUP)

10 / 68    (PUP)

2 / 68      (PUP)
http://www.mobogenie.com/.../Mobogenie_Setup_server2.exe  (092df016ea8d2f83356c08b6838e0542)

3 / 68      (PUP)
http://www.mobogenie.com/.../Mobogenie_Setup_server2.exe  (f6db71cf729a602dd606111599983131)

0 / 68

1 / 68      (PUP)
http://www.mobogenie.com/.../Mobogenie_Setup_2.1.9_21.exe  (ccfa78018a76bbf7362a9f830205eff1)

URL:
http://www.mobogenie.com/

Google Analytics:
UA-55537945

Title:
“Mobogenie - Android Market - Millions of Apps and Games Free Download”

Description:
“Download Mobogenie to get millions of free android apps, games, music, wallpapers, videos and eBooks. Mobogenie.com”

Network:
Amazon Web Services (AWS), running an EC2 instance

SSL certificate subject:
CN=*.mobogenie.com, OU=Terms of use at www.verisign.com/rpa (c)05, OU=Product Dept., O="Beijing AmazGame Age Internet Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

SSL certificate issuer:
CN=VeriSign Class 3 Secure Server CA - G3, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Web server:
Tengine