install-cdn.megabrowse.biz

Yontoo LLC  (via a Proxy Registrant)

Domain Information

install-cdn.megabrowse.biz is operated by Sambreel's (now QuestPoint) subsidiary Yontoo. The domain install-cdn.megabrowse.biz is registered by proxy through GODADDY.COM, INC. and was originally registered in January of 2014. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Seattle, Washington within the United States which resides on the Akamai Technologies, Inc. network. The domain is associated with the publisher Yontoo LLC who is located in Carlsbad, California in the United States.
Registrar:
GODADDY.COM, INC.

Server location:
Washington, United States (US)

Create date:
Monday, January 13, 2014

Expires date:
Thursday, January 12, 2017

Updated date:
Wednesday, January 13, 2016

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.MegaBrowse.F, PUP.Yontoo (M)
100.00%

NANO AntiVirus
Riskware.Win32.Agent.cqycvd
88.89%

Kaspersky
not-a-virus:AdWare.Win32.Agent
88.89%

Comodo Security
Application.Win32.Altbrowse.AK
88.89%

VIPRE Antivirus
Yontoo
88.89%

Vba32 AntiVirus
AdWare.Agent
88.89%

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
88.89%

Malwarebytes
PUP.Optional.MegaBrowse.A
88.89%

Trend Micro House Call
TROJ_GEN.F47V0307, TROJ_GE.203227CA, TROJ_GE.5058D345, TROJ_GEN.F47V0315, TROJ_GEN.F47V0311, TROJ_GEN.F47V0319, TROJ_GEN.F47V0314
88.89%

Dr.Web
Trojan.BPlug.28, Trojan.BPlug.10
77.78%

Sophos
Generic PUA LC, BrowseSmart, Generic PUA OF, Generic PUA HI, Generic PUA JP, Generic PUA AA
77.78%

ESET NOD32
Win32/BrowseFox (variant)
77.78%

McAfee
Artemis!FF671FFEDE31, Artemis!24B4ACD6CAF1, Artemis!748109873385, Artemis!D3E22248F72A, Artemis!22010145A3CD, Artemis!9C7CE7BB2A43
77.78%

Fortinet FortiGate
Adware/Agent
66.67%

K7 AntiVirus
Unwanted-Program
55.56%

The domain install-cdn.megabrowse.biz has been seen to resolve to the following 13 IP addresses.

a23-15-7-121.deploy.static.akamaitechnologies.com
June 7, 2016

a23-15-7-104.deploy.static.akamaitechnologies.com
June 7, 2016

a104-96-220-232.deploy.static.akamaitechnologies.com
May 26, 2016

a104-112-235-9.deploy.static.akamaitechnologies.com
May 26, 2016

a104-96-221-145.deploy.static.akamaitechnologies.com
May 20, 2016

a104-96-221-83.deploy.static.akamaitechnologies.com
May 20, 2016

a23-220-148-40.deploy.static.akamaitechnologies.com
May 16, 2016

a23-220-148-34.deploy.static.akamaitechnologies.com
May 16, 2016

a23-15-7-91.deploy.static.akamaitechnologies.com
April 13, 2016

a23-0-160-91.deploy.static.akamaitechnologies.com
March 3, 2016

a23-0-160-97.deploy.static.akamaitechnologies.com
March 3, 2016

a23-15-7-130.deploy.static.akamaitechnologies.com
February 8, 2016

a23-15-7-146.deploy.static.akamaitechnologies.com
February 8, 2016

File downloads found at URLs served by install-cdn.megabrowse.biz.

1 / 68      (Adware)
http://install-cdn.megabrowse.biz/setup.exe  (8a32defeb6f49a75bd51c747f9d92da5)

18 / 68    (Adware)
http://install-cdn.megabrowse.biz/setup.exe  (7989f928772a88f7a4d5fcdda89ec5d8)

18 / 68    (Adware)
http://install-cdn.megabrowse.biz/setup.exe  (d3e22248f72a2887c873f4ae7c31b248)

16 / 68    (Adware)
http://install-cdn.megabrowse.biz/setup.exe  (22010145a3cdfa7e57e505a0e118f5a7)

17 / 68    (Adware)
http://install-cdn.megabrowse.biz/setup.exe  (24b4acd6caf1c863ffd8acedd33f19a1)

15 / 68    (Adware)
http://install-cdn.megabrowse.biz/setup.exe  (9c7ce7bb2a43d9ec2a996b3f79b68146)

11 / 68    (Adware)
http://install-cdn.megabrowse.biz/setup.exe  (1ba4d5a58bb1e8c625ca676a9fa1345f)

17 / 68    (Adware)
http://install-cdn.megabrowse.biz/setup.exe  (ff671ffede31f964eefc2a1c2af6720c)

12 / 68    (Adware)
http://install-cdn.megabrowse.biz/setup.exe  (d8d74ec56216f620b7554721539c1f35)

The following 66 files have been seen to comunicate with install-cdn.megabrowse.biz in live environments.

 
Latest 20 of 69 files

URL:
http://install-cdn.megabrowse.biz/

Web server:
Microsoft-IIS/7.5 (ASP.NET)

30 of 37 related domains