The domain cdn.wifihotspotcreator.com registered by Jonathan Danucalov was initially registered in October of 2011 through GODADDY.COM, LLC. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below). The domain is associated with the publisher W3i, LLC who is located in Sartell, Minnesota in the United States.
Registrar:
GODADDY.COM, LLC
Server location:
Arizona, United States (US)
Create date:
Thursday, October 27, 2011
Expires date:
Thursday, October 27, 2016
Updated date:
Wednesday, November 4, 2015
ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US
Google Safe Browsing:
unwanted
Scanner detections:
Detections (73% detected)
Scan engine
Details
Detections
Dr.Web
Adware.W3i.9, Adware.W3i.32, Adware.Downware.1656, Adware.Downware.2512, Adware.W3i.45, Adware.Downware.8723
70.00%
Reason Heuristics
PUP.Installer.W3i.J, PUP.Installer.InstallX.X, PUP.Installer.SecureInstall.X, Threat.Win.Reputation.IMP, PUP.Installer.InstallX.V
70.00%
VIPRE Antivirus
InstallIQ Installer
60.00%
ESET NOD32
Win32/InstallIQ (variant)
60.00%
Malwarebytes
PUP.Optional.InstallIQ.A, PUP.Optional.InstallQ, PUP.Optional.SafeInstall.A
60.00%
Comodo Security
UnclassifiedMalware, Application.Win32.InstallIQ.B
50.00%
AVG
Skodna.Bundle, MalSign.InstallX, Win32/Heur, MultiBundle, InstallIQ
50.00%
Bkav FE
HW32.Laneul, W32.Clodc59.Trojan, W32.Clod259.Trojan, W32.Clod2e3.Trojan
40.00%
Rising Antivirus
PE:PUF.InstallIQ!1.9E4F
40.00%
McAfee
Artemis!7DC472F5C4A3, Artemis!2ABE8A697725, Artemis!33257E9B1F90, Artemis!DB2CD4FB5A6A
40.00%
Avira AntiVirus
APPL/InstallIQ.Gen5, TR/Agent.1611042
30.00%
Trend Micro House Call
TROJ_GEN.F47V1216, TROJ_GEN.F47V0429, TROJ_GEN.F47V1126
30.00%
NANO AntiVirus
Trojan.Win32.Searcher.cjaztx, Riskware.Win32.Searcher.csnymk, Riskware.Win32.Searcher.cjaztx
30.00%
IKARUS anti.virus
AdWare.InstallIQ, Virus.Win32.Heur
30.00%
avast!
Win32:Adware-gen [Adw], Win32:Dropper-gen [Drp]
30.00%
The domain cdn.wifihotspotcreator.com has been seen to resolve to the following 6 IP addresses.
File downloads found at URLs served by cdn.wifihotspotcreator.com.
URL:
http://cdn.wifihotspotcreator.com/
SSL certificate subject:
CN=sni10960.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated
SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB
Web server:
cloudflare-nginx
Statistics are for the previous month.
Related Domains