si.gboxapp.com

webpick ltd

Domain Information

The domain si.gboxapp.com registered by webpick ltd was initially registered in December of 2011 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Wednesday, December 7, 2011

Expires date:
Monday, December 7, 2015

Updated date:
Sunday, August 4, 2013

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Malwarebytes
PUP.Optional.MultiPlug.A
100.00%

Zillya! Antivirus
Trojan.Chifrax.Win32.4568
100.00%

AegisLab AV Signature
Hoax.W32.ArchSMS
100.00%

Clam AntiVirus
Win.Trojan.Agent-763007
100.00%

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
100.00%

The domain si.gboxapp.com has been seen to resolve to the following 2 IP addresses.

October 9, 2014

October 9, 2014

File downloads found at URLs served by si.gboxapp.com.

5 / 68      (PUP)
http://si.gboxapp.com/si.exe  (7695de4c1c9d2c35b0c1892acf87fb97)

URL:
http://si.gboxapp.com/

SSL certificate subject:
CN=sni65600.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx