installer-14b7.kxcdn.com

proinity GmbH

Domain Information

The domain installer-14b7.kxcdn.com registered by proinity GmbH was initially registered in January of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Manassas, Virginia within the United States which resides on the Leaseweb USA, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Virginia, United States (US)

Create date:
Wednesday, January 30, 2013

Expires date:
Monday, January 30, 2017

Updated date:
Wednesday, November 19, 2014

ASN:
AS30633 LEASEWEB-US - Leaseweb USA, Inc.,US

Root domain:

Scanner detections:
Detections  (75% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Amonitize.OpenSource.Installer (M)
100.00%

Quick Heal
RiskTool.BitCoinMin.09327
33.33%

K7 AntiVirus
Unwanted-Program
33.33%

ESET NOD32
Win32/BitCoinMiner.BY potentially unsafe (variant)
33.33%

avast!
Multi:BitCoinMiner-B [PUP]
33.33%

Kaspersky
not-a-virus:HEUR:RiskTool.Win32.BitCoinMiner
33.33%

Agnitum Outpost
Riskware.Agent
33.33%

Dr.Web
Trojan.BtcMine.730
33.33%

VIPRE Antivirus
Trojan.Win32.Generic
33.33%

Sophos
CpuMiner (PUA)
33.33%

Avira AntiVirus
TR/BitCoinMiner.4628256
33.33%

AhnLab V3 Security
Unwanted/Win32.BitCoinMiner
33.33%

IKARUS anti.virus
PUA.BitCoinMiner
33.33%

AVG
Generic_r
33.33%

The domain installer-14b7.kxcdn.com has been seen to resolve to the following 2 IP addresses.

hosted-by.Eqserver.com
February 27, 2016

February 21, 2016

File downloads found at URLs served by installer-14b7.kxcdn.com.

0 / 68
http://installer-14b7.kxcdn.com/Installer.exe  (730d6a033c38c44c1eec155393d15c9f)

1 / 68      (Adware)

14 / 68    (Adware)
http://installer-14b7.kxcdn.com/Installer.exe  (1d7dec236187389ae89e5fa7f4e30ed4)

1 / 68      (Adware)

The following 7 files have been seen to comunicate with installer-14b7.kxcdn.com in live environments.

URL:
http://installer-14b7.kxcdn.com/

SSL certificate subject:
CN=*.kxcdn.com, OU=PositiveSSL Wildcard, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
keycdn-engine