cdn.winweatherforecast.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain cdn.winweatherforecast.com is registered by proxy through ENOM, INC. and was originally registered in January of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in United, Pennsylvania within the United States which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Pennsylvania, United States (US)

Create date:
Monday, January 25, 2016

Expires date:
Thursday, January 25, 2018

Updated date:
Friday, April 1, 2016

ASN:
AS60068 CDN77 Datacamp Limited,GB

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (95% detected)

Scan engine
Details
Detections

Kaspersky
not-a-virus:AdWare.Win32.AdLoad
94.74%

ESET NOD32
Win32/Adware.AppShake.A application
94.74%

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.102921
78.95%

F-Secure
Variant.Midie.7630, Variant.Graftor.272663, Variant.Graftor.271926
78.95%

Norman
Gen:Variant.Adware.Strictor.102921
68.42%

Reason Heuristics
Adware.Generic.AT (M), PUP.EasyVpn (M)
26.32%

avast!
Win32:Adware-gen [Adw]
21.05%

VIPRE Antivirus
Threat.4150696
15.79%

Dr.Web
Detection.Undefined
5.26%

The domain cdn.winweatherforecast.com has been seen to resolve to the following 7 IP addresses.

new-york-20.cdn77.com
May 18, 2016

new-york-20.cdn77.com
May 17, 2016

new-york-20.cdn77.com
April 18, 2016

new-york-20.cdn77.com
April 18, 2016

new-york-20.cdn77.com
April 14, 2016

atlanta-4.cdn77.com
April 13, 2016

atlanta-3.cdn77.com
April 12, 2016

File downloads found at URLs served by cdn.winweatherforecast.com.

8 / 68      (PUP)

7 / 68      (PUP)

5 / 68      (PUP)

The following 7 files have been seen to comunicate with cdn.winweatherforecast.com in live environments.

URL:
http://cdn.winweatherforecast.com/

Title:
“Your Push Zone has been created.”

SSL certificate subject:
CN=1324759374.rsc.cdn77.org

SSL certificate issuer:
CN=Let's Encrypt Authority X3, O=Let's Encrypt, C=US

Web server:
CDN77-Turbo