671e17cc-a-62cb3a1a-s-sites.googlegroups.com

Google Inc.

Domain Information

The domain 671e17cc-a-62cb3a1a-s-sites.googlegroups.com registered by Google Inc. was initially registered in February of 2001 through MARKMONITOR INC.. Currently this domain has been known to host various forms of malware. The hosted servers are located in Mountain View, California within the United States which resides on the Google Inc. network.
Registrar:
MARKMONITOR INC.

Server location:
California, United States (US)

Create date:
Tuesday, February 27, 2001

Expires date:
Monday, February 27, 2017

Updated date:
Tuesday, January 26, 2016

ASN:
AS15169 GOOGLE - Google Inc.

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Bkav FE
W32.HfsAutoB
100.00%

MicroWorld eScan
Gen:Trojan.Heur.RP.1y0aaKLtmbf
100.00%

Quick Heal
(Suspicious) - DNAScan
100.00%

Bitdefender
Gen:Trojan.Heur.RP.1y0aaKLtmbf
100.00%

ESET NOD32
Win32/Packed.Themida.ABG (variant)
100.00%

avast!
Win32:Evo-gen [Susp]
100.00%

Lavasoft Ad-Aware
Gen:Trojan.Heur.RP.1y0aaKLtmbf
100.00%

Comodo Security
TrojWare.Win32.Agent.COC
100.00%

F-Secure
Gen:Trojan.Heur.RP.1y0aaKLtmbf
100.00%

Emsisoft Anti-Malware
Gen:Trojan.Heur.RP.1y0aaKLtmbf
100.00%

Avira AntiVirus
TR/Spy.Agent.873984.9
100.00%

Arcabit
Trojan.Heur.RP.1y0aaKLtmbf
100.00%

G Data
Gen:Trojan.Heur.RP.1y0aaKLtmbf
100.00%

Fortinet FortiGate
PossibleThreat
100.00%

The domain 671e17cc-a-62cb3a1a-s-sites.googlegroups.com has been seen to resolve to the following IP address.

qg-in-f137.1e100.net
February 12, 2016

File downloads found at URLs served by 671e17cc-a-62cb3a1a-s-sites.googlegroups.com.

URL:
http://671e17cc-a-62cb3a1a-s-sites.googlegroups.com/

Title:
“Google Sites”

Description:
“Thinking of creating a website? Google Sites is a free and easy way to create and share webpages.”

SSL certificate subject:
CN=*.googlegroups.com, O=Google Inc, L=Mountain View, S=California, C=US

SSL certificate issuer:
CN=Google Internet Authority G2, O=Google Inc, C=US

Web server:
GSE