install.cytiweb.net
Domains By Proxy, LLC (Proxy Registrant)
Domain Information
The domain install.cytiweb.net is registered by proxy through GODADDY.COM, LLC and was originally registered in February of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Warsaw, Mazowieckie within Poland which resides on the Akamai Technologies, Inc. network.
Registrant:
Domains By Proxy, LLC
Registrar:
GODADDY.COM, LLC
Server location:
Mazowieckie, Poland (PL)
Create date:
Tuesday, February 4, 2014
Expires date:
Saturday, February 4, 2017
Updated date:
Thursday, February 4, 2016
ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V., US
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.Yontoo.CytiWeb (M), PUP.Yontoo.Girafarr (M)
100.00%
The domain install.cytiweb.net has been seen to resolve to the following 3 IP addresses.
a104-96-220-177.deploy.static.akamaitechnologies.com
June 21, 2016
a104-96-220-136.deploy.static.akamaitechnologies.com
June 21, 2016
File downloads found at URLs served by install.cytiweb.net.
The following 21 files have been seen to comunicate with install.cytiweb.net in live environments.
URL:
http://install.cytiweb.net/
SSL certificate subject:
CN=*.cytiweb.net
SSL certificate issuer:
CN=RapidSSL SHA256 CA - G3, O=GeoTrust Inc., C=US
Web server:
Microsoft-IIS/7.5 (ASP.NET)