install-cdn.betweenlinesnow.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain install-cdn.betweenlinesnow.com is registered by proxy through GODADDY.COM, LLC and was originally registered in February of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Cambridge, Massachusetts within the United States which resides on the Akamai Technologies, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Massachusetts, United States (US)

Create date:
Wednesday, February 18, 2015

Expires date:
Sunday, February 18, 2018

Updated date:
Monday, March 21, 2016

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

NANO AntiVirus
Trojan.Win32.Yontoo.dnkubo
100.00%

F-Prot
W32/S-9c4b2ea6
100.00%

Dr.Web
Trojan.Yontoo.1016, Trojan.Yontoo.1735, Trojan.Yontoo.1734
100.00%

Vba32 AntiVirus
AdWare.MSIL.Agent
100.00%

IKARUS anti.virus
AdWare.BrowseFox, not-a-virus:AdWare.Win32.Agent
100.00%

Baidu Antivirus
Adware.Win32.BrowseFox
100.00%

Reason Heuristics
PUP.BHO.Yontoo, PUP.Yontoo, Threat.Yontoo.BetweenLines
100.00%

K7 AntiVirus
Trojan
100.00%

Avira AntiVirus
ADWARE/BrowseFox.Gen2, TR/Trash.Gen
90.00%

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
90.00%

McAfee
Artemis!695686A76A25, Artemis!F2823AD93F19, Artemis!4D0808C98C85, Artemis!673F48A4ED7F, Artemis!B3969FE4B745
90.00%

Malwarebytes
PUP.Optional.BetweenLines.A
90.00%

Trend Micro House Call
Suspicious_GEN.F47V0317, Suspicious_GEN.F47V0318, TROJ_GEN.R047C0OD815, TROJ_GEN.R00UC0OCR15
90.00%

Agnitum Outpost
Riskware.Agent
90.00%

VIPRE Antivirus
Trojan.Win32.Generic
90.00%

The domain install-cdn.betweenlinesnow.com has been seen to resolve to the following 18 IP addresses.

a23-15-9-66.deploy.static.akamaitechnologies.com
July 21, 2016

a23-15-9-11.deploy.static.akamaitechnologies.com
July 21, 2016

a72-246-64-131.deploy.akamaitechnologies.com
May 25, 2016

a72-246-64-130.deploy.akamaitechnologies.com
May 25, 2016

a104-96-221-121.deploy.static.akamaitechnologies.com
May 18, 2016

a104-96-221-88.deploy.static.akamaitechnologies.com
May 18, 2016

a104-96-220-178.deploy.static.akamaitechnologies.com
May 17, 2016

a104-96-220-105.deploy.static.akamaitechnologies.com
May 17, 2016

a104-96-220-138.deploy.static.akamaitechnologies.com
May 17, 2016

a23-62-6-80.deploy.static.akamaitechnologies.com
April 13, 2016

February 29, 2016

February 29, 2016

a23-0-160-33.deploy.static.akamaitechnologies.com
February 27, 2016

a23-0-160-16.deploy.static.akamaitechnologies.com
February 27, 2016

a23-62-6-67.deploy.static.akamaitechnologies.com
February 23, 2016

a23-62-6-59.deploy.static.akamaitechnologies.com
February 23, 2016

a23-15-8-203.deploy.static.akamaitechnologies.com
February 8, 2016

a23-15-8-226.deploy.static.akamaitechnologies.com
February 8, 2016

File downloads found at URLs served by install-cdn.betweenlinesnow.com.

19 / 68    (Adware)

20 / 68    (Adware)

30 / 68    (Adware)

19 / 68    (Adware)

12 / 68    (Adware)

20 / 68    (Adware)

20 / 68    (Adware)

27 / 68    (Adware)

20 / 68    (Adware)

20 / 68    (Adware)

20 / 68    (Adware)

19 / 68    (Adware)

30 / 68    (Adware)

20 / 68    (Adware)

20 / 68    (Adware)

30 / 68    (Adware)

30 / 68    (Adware)

30 / 68    (Adware)

12 / 68    (Adware)

20 / 68    (Adware)

20 / 68    (Adware)

The following 164 files have been seen to comunicate with install-cdn.betweenlinesnow.com in live environments.

 
Latest 20 of 179 files

URL:
http://install-cdn.betweenlinesnow.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET)