cdnrep.reimageplus.com
Crossrider Advanced Technologies Ltd. (via a Proxy Registrant)
Domain Information
The domain cdnrep.reimageplus.com is registered by proxy through GODADDY.COM, LLC and was originally registered in January of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the Highwinds Network Group, Inc. network. The domain is associated with the publisher Crossrider Advanced Technologies Ltd..
Registrant:
Domains By Proxy, LLC on behalf of Crossrider Advanced Technologies Ltd.
Registrar:
GODADDY.COM, LLC
Server location:
Arizona, United States (US)
Create date:
Tuesday, January 3, 2012
Expires date:
Wednesday, January 3, 2018
Updated date:
Monday, January 4, 2016
ASN:
AS20446 HIGHWINDS3 - Highwinds Network Group, Inc.,US
Scanner detections:
Detections (96% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Reimage (L), Win32.Generic.Reimage.Installer.Meta, PUP.Reimage.Optional.Installer.Meta (L), PUP.Reimage.Optional.Meta (L), PUP.Reimage.ReimageR.Installer.Meta (L), PUP.Reimage.Installer.Meta (L)
96.00%
Dr.Web
riskware program Program.Unwanted.493, riskware program Program.Unwanted.497, riskware program Program.Unwanted.1470
40.00%
Bkav FE
W32.HfsAdware
24.00%
McAfee
Artemis!72CB31555DA5, Artemis!D7830F8B35ED, Artemis!5FC7934C9790, Artemis!B3C7121FD4C9
24.00%
Fortinet FortiGate
Riskware/ReImageRepair
24.00%
Baidu Antivirus
PUA.Win32.ReImageRepair
24.00%
Malwarebytes
PUP.Optional.ReImageRepair.A
16.00%
Trend Micro House Call
Suspicious_GEN.F47V0520, Suspicious_GEN.F47V0528
16.00%
ESET NOD32
Detection.Undefined, Win32/ReImageRepair.F potentially unwanted application
12.00%
ESET NOD32
Win32/ReImageRepair.F potentially unwanted
12.00%
G Data
Win32.Application.ReImageRepair
8.00%
VIPRE Antivirus
Trojan.Win32.Generic
8.00%
Microsoft Security Essentials
Worm:Win32/NeksMiner.A
4.00%
The domain cdnrep.reimageplus.com has been seen to resolve to the following IP address.
vip080.ssl.hwcdn.net
October 29, 2015
File downloads found at URLs served by cdnrep.reimageplus.com.
The following 137 files have been seen to comunicate with cdnrep.reimageplus.com in live environments.
Related Domains