cdn.wifihotspotcreator.com

W3i, LLC

Domain Information

The domain cdn.wifihotspotcreator.com registered by Jonathan Danucalov was initially registered in October of 2011 through GODADDY.COM, LLC. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below). The domain is associated with the publisher W3i, LLC who is located in Sartell, Minnesota in the United States.
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Thursday, October 27, 2011

Expires date:
Thursday, October 27, 2016

Updated date:
Wednesday, November 4, 2015

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (73% detected)

Scan engine
Details
Detections

Dr.Web
Adware.W3i.9, Adware.W3i.32, Adware.Downware.1656, Adware.Downware.2512, Adware.W3i.45, Adware.Downware.8723
70.00%

Reason Heuristics
PUP.Installer.W3i.J, PUP.Installer.InstallX.X, PUP.Installer.SecureInstall.X, Threat.Win.Reputation.IMP, PUP.Installer.InstallX.V
70.00%

VIPRE Antivirus
InstallIQ Installer
60.00%

ESET NOD32
Win32/InstallIQ (variant)
60.00%

Malwarebytes
PUP.Optional.InstallIQ.A, PUP.Optional.InstallQ, PUP.Optional.SafeInstall.A
60.00%

Comodo Security
UnclassifiedMalware, Application.Win32.InstallIQ.B
50.00%

AVG
Skodna.Bundle, MalSign.InstallX, Win32/Heur, MultiBundle, InstallIQ
50.00%

Bkav FE
HW32.Laneul, W32.Clodc59.Trojan, W32.Clod259.Trojan, W32.Clod2e3.Trojan
40.00%

Rising Antivirus
PE:PUF.InstallIQ!1.9E4F
40.00%

McAfee
Artemis!7DC472F5C4A3, Artemis!2ABE8A697725, Artemis!33257E9B1F90, Artemis!DB2CD4FB5A6A
40.00%

Avira AntiVirus
APPL/InstallIQ.Gen5, TR/Agent.1611042
30.00%

Trend Micro House Call
TROJ_GEN.F47V1216, TROJ_GEN.F47V0429, TROJ_GEN.F47V1126
30.00%

NANO AntiVirus
Trojan.Win32.Searcher.cjaztx, Riskware.Win32.Searcher.csnymk, Riskware.Win32.Searcher.cjaztx
30.00%

IKARUS anti.virus
AdWare.InstallIQ, Virus.Win32.Heur
30.00%

avast!
Win32:Adware-gen [Adw], Win32:Dropper-gen [Drp]
30.00%

The domain cdn.wifihotspotcreator.com has been seen to resolve to the following 6 IP addresses.

April 6, 2016

April 6, 2016

March 9, 2015

March 9, 2015

August 17, 2014

January 17, 2014

File downloads found at URLs served by cdn.wifihotspotcreator.com.

0 / 68

2 / 68      (PUP)

8 / 68      (Adware)

11 / 68    (Adware)

1 / 68      (inconclusive)

3 / 68      (PUP)

21 / 68    (PUP)

10 / 68    (Adware)

2 / 68

11 / 68    (Adware)

26 / 68    (Adware)

URL:
http://cdn.wifihotspotcreator.com/

Title:
“Index of /”

SSL certificate subject:
CN=sni10960.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx

Facebook:
Shares:  3

Statistics are for the previous month.