b3-31d2.kxcdn.com

proinity GmbH

Domain Information

The domain b3-31d2.kxcdn.com registered by proinity GmbH was initially registered in January of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Manassas, Virginia within the United States which resides on the Leaseweb USA, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Wednesday, January 30, 2013

Expires date:
Monday, January 30, 2017

Updated date:
Wednesday, November 19, 2014

ASN:
AS30633 LEASEWEB-US - Leaseweb USA, Inc.,US

Root domain:

Scanner detections:
Detections  (71% detected)

Scan engine
Details
Detections

Dr.Web
Detection.Undefined, Win32.Sector.30
66.67%

Emsisoft Anti-Malware
Gen:Variant.Application.BitcoinMiner.16, Win32.Sality
50.00%

ESET NOD32
Win32/BitCoinMiner.BY potentially unsafe application, Win32/Sality.NBA virus
50.00%

McAfee
Program.Artemis!F2660856ABE2, Program.PUP-RHAI, Virus.PUP-RHAI
50.00%

Kaspersky
not-a-virus:RiskTool.Win32.BitCoinMiner, Virus.Win32.Sality
50.00%

Norman
Gen:Variant.Application.BitcoinMiner.16, Win32.Sality.3
50.00%

Reason Heuristics
Adware.Amonetize.OpenSource.Installer.Meta (M), Adware.Amonetize.OpenSour.Installer.Meta (M)
33.33%

F-Secure
Variant.Application.BitcoinMiner, Win32.Sality.3
33.33%

F-Prot
W32/Sality.gen2
16.67%

Microsoft Security Essentials
Threat.Undefined
16.67%

avast!
Win32:Sality
16.67%

The domain b3-31d2.kxcdn.com has been seen to resolve to the following 2 IP addresses.

June 4, 2016

hosted-by.Eqserver.com
June 4, 2016

File downloads found at URLs served by b3-31d2.kxcdn.com.

0 / 68
http://b3-31d2.kxcdn.com/B3.exe  (5663b94f903512e2cd97c45dd2fc867d)

1 / 68      (inconclusive)
http://b3-31d2.kxcdn.com/B3.exe  (7b767cb92a473f504ab263d30cf77859)

10 / 68    (Malware)
http://b3-31d2.kxcdn.com/B3.exe  (d0ef5b5daffdec32556eb9fc5dea0e1f)

1 / 68      (PUP)
http://b3-31d2.kxcdn.com/B3.exe  (ic-0.60852a874cf8cc.exe)

1 / 68      (PUP)

6 / 68      (PUP)
http://b3-31d2.kxcdn.com/B3.exe  (ic-0.e877a613d48d.exe)

7 / 68      (PUP)
http://b3-31d2.kxcdn.com/B3.exe  (9ec2df37712410ac943771acdd4672cd)

The following 7 files have been seen to comunicate with b3-31d2.kxcdn.com in live environments.

URL:
http://b3-31d2.kxcdn.com/

SSL certificate subject:
CN=*.kxcdn.com, OU=PositiveSSL Wildcard, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
keycdn-engine