The domain install-cdn.gatesnapper.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Seattle, Washington within the United States which resides on the Akamai Technologies, Inc. network.
Registrant:
Domains By Proxy, LLC
Registrar:
GODADDY.COM, LLC
Server location:
Washington, United States (US)
Create date:
Tuesday, March 18, 2014
Expires date:
Saturday, March 18, 2017
Updated date:
Saturday, March 19, 2016
ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
Threat.Win.Reputation.IMP, PUP.Yontoo, PUP.BHO.Yontoo, Threat.Yontoo.gatesnapper, PUP.Yontoo.gatesnapper, PUP.Yontoo.gatesnapper (M), PUP.Yontoo.gatesnap (M)
100.00%
Avira AntiVirus
ADWARE/BrowseFox.Gen2, APPL/BrowseFox.Gen2
96.88%
Baidu Antivirus
Adware.Win32.BrowseFox
96.88%
AVG
BrowseFox.F, Adware BrowseFox.F, Generic, Adware AdPlugin.DIU
96.88%
Malwarebytes
PUP.Optional.GateSnapper.A, PUP.Optional.Zebar.A, PUP.Optional.JumpFlip.A
93.75%
K7 AntiVirus
Trojan
90.63%
F-Prot
W32/S-7bed2e86, W32/BadBHO.AW.gen, W32/S-9c4b2ea6
90.63%
NANO AntiVirus
Trojan.Win32.BPlug.ddwtte, Riskware.Win32.Agent.czmzab, Trojan.Win32.BPlug.dfogbn, Trojan.Win32.Yontoo.dnkubo
90.63%
Dr.Web
Trojan.BPlug.142, Trojan.BPlug.215, Trojan.Yontoo.1016, Trojan.Yontoo.1734
90.63%
Vba32 AntiVirus
AdWare.Kranet, AdWare.MSIL.Agent
90.63%
Comodo Security
Application.Win32.BrowseFox.JM, Application.Win32.Altbrowse.AK
87.50%
Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen, HEUR/Malware.QVM30.Gen
84.38%
Emsisoft Anti-Malware
Gen:Variant.Adware.BHO.Agent, Adware.BrowseFox.BJ, Gen:Variant.Mikey.11547, Adware.BrowseFox.CY
84.38%
Bitdefender
Gen:Variant.Adware.BHO.Agent.4, Adware.BrowseFox.BJ, Adware.BrowseFox.CY
84.38%
McAfee
Artemis!CD96DF17AA75, BrowseFox, Artemis!F3F6C437852D, Artemis!668D770DAE0C, Artemis!FFC9829C5FC8, BrowseFox-FRR
84.38%
The domain install-cdn.gatesnapper.com has been seen to resolve to the following 24 IP addresses.
a23-15-8-232.deploy.static.akamaitechnologies.com
July 20, 2016
a104-96-220-120.deploy.static.akamaitechnologies.com
June 29, 2016
a104-96-220-144.deploy.static.akamaitechnologies.com
May 15, 2016
a104-96-220-138.deploy.static.akamaitechnologies.com
May 15, 2016
a184-51-126-147.deploy.static.akamaitechnologies.com
April 7, 2016
a184-51-126-128.deploy.static.akamaitechnologies.com
April 7, 2016
a23-15-8-211.deploy.static.akamaitechnologies.com
April 6, 2016
a23-15-8-226.deploy.static.akamaitechnologies.com
April 6, 2016
a23-15-7-105.deploy.static.akamaitechnologies.com
April 5, 2016
a23-15-7-107.deploy.static.akamaitechnologies.com
April 5, 2016
a23-62-6-83.deploy.static.akamaitechnologies.com
April 5, 2016
a23-62-6-97.deploy.static.akamaitechnologies.com
April 5, 2016
a23-0-160-57.deploy.static.akamaitechnologies.com
March 4, 2016
a23-0-160-51.deploy.static.akamaitechnologies.com
March 4, 2016
a184-26-143-112.deploy.static.akamaitechnologies.com
February 28, 2016
a184-26-143-113.deploy.static.akamaitechnologies.com
February 28, 2016
a23-62-7-138.deploy.static.akamaitechnologies.com
February 28, 2016
a23-62-7-168.deploy.static.akamaitechnologies.com
February 28, 2016
File downloads found at URLs served by install-cdn.gatesnapper.com.
Latest 30 of 34 download URLs
The following 201 files have been seen to comunicate with install-cdn.gatesnapper.com in live environments.
URL:
http://install-cdn.gatesnapper.com/
Web server:
Microsoft-IIS/7.5 (ASP.NET)