zr3mzw.bn1301.livefilestore.com

Microsoft Corporation

Domain Information

The domain zr3mzw.bn1301.livefilestore.com registered by Microsoft Corporation was initially registered in January of 2007 through CSC CORPORATE DOMAINS, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Redmond, Washington within the United States which resides on the Microsoft Corp network.
Remove Malware from zr3mzw.bn1301.livefilestore.com - Powered by Reason Core Security
Registrar:
CSC CORPORATE DOMAINS, INC.

Server location:
Washington, United States (US)

Create date:
Tuesday, January 30, 2007

Expires date:
Friday, January 30, 2015

Updated date:
Monday, January 27, 2014

ASN:
AS8075 MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation

Root domain:

Scanner detections:
Detections  (67% detected)

Scan engine
Details
Detections

F-Prot
W32/FakeInstall.A.gen
66.67%

McAfee
Artemis!263F48F3CD9B, Artemis!F31B3D53E02E
66.67%

Trend Micro House Call
TROJ_GEN.R047H05CH14, TROJ_GEN.F47V0325
66.67%

Dr.Web
Adware.Downware.2013
66.67%

McAfee Web Gateway
Artemis!263F48F3CD9B, Artemis!F31B3D53E02E
66.67%

ESET NOD32
Win32/InstallMonetizer.AQ
66.67%

K7 Gateway Antivirus
Trojan
33.33%

K7 AntiVirus
Trojan
33.33%

Norman
Suspicious_Gen4.FYNBI
33.33%

VIPRE Antivirus
Trojan.Win32.Generic
33.33%

Avira AntiVirus
DR/Delphi.Gen
33.33%

The domain zr3mzw.bn1301.livefilestore.com has been seen to resolve to the following 3 IP addresses.

March 15, 2014

March 14, 2014

February 6, 2014

File downloads found at URLs served by zr3mzw.bn1301.livefilestore.com.

10 / 68    (PUP)

1 / 68

6 / 68      (PUP)

1 / 68

1 / 68

1 / 68

The following 2 files have been seen to comunicate with zr3mzw.bn1301.livefilestore.com in live environments.

URL:
http://zr3mzw.bn1301.livefilestore.com/

SSL certificate subject:
CN=storage.live.com, OU=OneDrive, O=Microsoft, L=Redmond, S=WA, C=US

SSL certificate issuer:
CN=MSIT Machine Auth CA 2, DC=redmond, DC=corp, DC=microsoft, DC=com

Web server:
Microsoft-HTTPAPI/2.0

Remove Malware from zr3mzw.bn1301.livefilestore.com - Powered by Reason Core Security