The domain install-cdn.cytiweb.net is registered by proxy through GODADDY.COM, LLC and was originally registered in February of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Akamai Technologies, Inc. network.
Registrant:
Domains By Proxy, LLC
Registrar:
GODADDY.COM, LLC
Server location:
New York, United States (US)
Create date:
Tuesday, February 4, 2014
Expires date:
Saturday, February 4, 2017
Updated date:
Thursday, February 4, 2016
ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US
Scanner detections:
Detections (98% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Installer.CytiWeb.M, PUP.CytiWeb.J, PUP.CytiWeb.I, PUP.CytiWeb.K, PUP.CytiWeb.G, PUP.BHO.CytiWeb.K, PUP.BHO.Yontoo, PUP.Yontoo, PUP.Yontoo.Girafarri.Installer (M), PUP.Yontoo.CytiWeb.Installer (M), PUP.Yontoo.Girafarr.Installer (M), PUP.Yontoo (M)
95.83%
NANO AntiVirus
Trojan.Win32.BPlug.dfsehz, Riskware.Win32.SwiftBrowse.dlbdsd, Trojan.Win32.BPlug.dfogbn, Trojan.Win32.Yontoo.dnkubo
62.50%
Dr.Web
Trojan.BPlug.181, infected with Trojan.BPlug.181, Trojan.Yontoo.476, Trojan.Yontoo.475, Trojan.BPlug.31, Trojan.BPlug.215
62.50%
AVG
Generic, BrowseFox.F, Adware BrowseFox.F, Girafarri, BrowseFox.H, Adware BrowseFox.H, Adware BrowseFox.G
62.50%
Malwarebytes
PUP.Optional.BPlug, PUP.Optional.CytiWeb.A
60.42%
Avira AntiVirus
ADWARE/BrowseFox.Gen, ADWARE/BrowseFox.Gen2
60.42%
Baidu Antivirus
Adware.Win32.BrowseFox
60.42%
G Data
NSIS.Application.BrowseFox, Adware.BrowseFox.BF, Gen:Variant.Adware.BHO.Agent, Adware.BrowseFox.BJ
58.33%
VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696, Yontoo
56.25%
AhnLab V3 Security
PUP/Win32.SwiftBrowse, Adware/Win32.BrowseFox, PUP/Win32.BrowseFox
56.25%
F-Prot
W32/S-b5aa130f, W32/S-7bed2e86, W32/S-c9f3cc61, W32/S-304afd20, W32/Adware.ALRY (exact, not disinfectable)
56.25%
Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen, Malware.QVM06.Gen, Win32/Virus.Adware.80e, HEUR/QVM30.1.Malware.Gen
52.08%
ESET NOD32
Win32/BrowseFox, Win32/BrowseFox (variant), Win32/BrowseFox.C potentially unwanted, Win32/BrowseFox.AE potentially unwanted
45.83%
K7 AntiVirus
Trojan , Unwanted-Program , DoS-Trojan
45.83%
Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF, PE:Trojan.Win32.Generic.17D5649F!399860895, PE:Malware.Kranet!6.20B9
43.75%
The domain install-cdn.cytiweb.net has been seen to resolve to the following 40 IP addresses.
a23-15-9-8.deploy.static.akamaitechnologies.com
July 21, 2016
a104-96-220-153.deploy.static.akamaitechnologies.com
July 17, 2016
a104-96-220-178.deploy.static.akamaitechnologies.com
June 28, 2016
a104-96-220-179.deploy.static.akamaitechnologies.com
June 28, 2016
a23-201-103-138.deploy.static.akamaitechnologies.com
May 25, 2016
a23-201-103-144.deploy.static.akamaitechnologies.com
May 25, 2016
a104-96-220-169.deploy.static.akamaitechnologies.com
May 15, 2016
a104-96-220-185.deploy.static.akamaitechnologies.com
May 15, 2016
a23-62-6-131.deploy.static.akamaitechnologies.com
April 14, 2016
a23-62-6-122.deploy.static.akamaitechnologies.com
April 14, 2016
a23-15-7-122.deploy.static.akamaitechnologies.com
April 6, 2016
a23-62-6-81.deploy.static.akamaitechnologies.com
April 5, 2016
a72-247-8-122.deploy.akamaitechnologies.com
March 3, 2016
a72-247-8-139.deploy.akamaitechnologies.com
March 3, 2016
a23-15-9-75.deploy.static.akamaitechnologies.com
March 3, 2016
a23-15-9-19.deploy.static.akamaitechnologies.com
March 3, 2016
a72-247-10-11.deploy.akamaitechnologies.com
March 2, 2016
a72-247-10-49.deploy.akamaitechnologies.com
March 2, 2016
a23-15-7-91.deploy.static.akamaitechnologies.com
February 27, 2016
a23-15-7-138.deploy.static.akamaitechnologies.com
February 27, 2016
a184-51-126-96.deploy.static.akamaitechnologies.com
February 27, 2016
a184-51-126-75.deploy.static.akamaitechnologies.com
February 27, 2016
a23-62-6-59.deploy.static.akamaitechnologies.com
February 23, 2016
a23-62-6-97.deploy.static.akamaitechnologies.com
February 23, 2016
Showing 30 of 40 IP Addresses
File downloads found at URLs served by install-cdn.cytiweb.net.
The following 317 files have been seen to comunicate with install-cdn.cytiweb.net in live environments.
URL:
http://install-cdn.cytiweb.net/
Web server:
Microsoft-IIS/7.5 (ASP.NET)