arabyads.go2cloud.org

1&1 Internet Inc

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in San Francisco, California within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Northern California) region datacenter.
Registrar:
1 & 1 Internet AG

Server location:
California, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.AnchorFree.Bundler.Meta (L), PUP.AnchorFree.HSS.Installer.Meta (M)
85.71%

VIPRE Antivirus
Threat.4167477
14.29%

herdProtect (fuzzy)
a variant of 5bfb7a52c9c5f3f31e88b4affce6ed5d7fd8fd17
14.29%

MicroWorld eScan
Win32.Neshta.A
14.29%

nProtect
Virus/W32.Neshta
14.29%

Quick Heal
W32.Neshta.A
14.29%

McAfee
W32/HLLP.41472.e
14.29%

Malwarebytes
Trojan.Agent
14.29%

K7 AntiVirus
Virus
14.29%

K7 Gateway Antivirus
Virus
14.29%

The Hacker
W32/Netshta.gen
14.29%

NANO AntiVirus
Virus.Win32.Neshta.cdby
14.29%

F-Prot
W32/HLLP.41472
14.29%

Norman
Neshta.C
14.29%

The domain arabyads.go2cloud.org has been seen to resolve to the following 19 IP addresses.

ec2-52-7-213-252.compute-1.amazonaws.com
July 17, 2016

ec2-52-206-36-195.compute-1.amazonaws.com
July 17, 2016

ec2-52-5-14-12.compute-1.amazonaws.com
July 5, 2016

ec2-52-87-124-218.compute-1.amazonaws.com
July 5, 2016

ec2-52-203-146-90.compute-1.amazonaws.com
June 6, 2016

ec2-52-72-162-128.compute-1.amazonaws.com
June 6, 2016

ec2-52-5-57-82.compute-1.amazonaws.com
June 6, 2016

ec2-54-208-124-218.compute-1.amazonaws.com
June 6, 2016

ec2-52-7-74-56.compute-1.amazonaws.com
May 16, 2016

ec2-52-73-92-190.compute-1.amazonaws.com
May 16, 2016

ec2-107-21-44-249.compute-1.amazonaws.com
April 21, 2016

ec2-52-72-118-27.compute-1.amazonaws.com
April 21, 2016

ec2-54-241-186-17.us-west-1.compute.amazonaws.com
October 9, 2014

ec2-54-183-42-248.us-west-1.compute.amazonaws.com
September 6, 2014

ec2-107-23-165-131.compute-1.amazonaws.com
August 7, 2014

ec2-107-21-52-90.compute-1.amazonaws.com
August 7, 2014

ec2-107-23-142-44.compute-1.amazonaws.com
August 7, 2014

ec2-54-241-149-139.us-west-1.compute.amazonaws.com
June 20, 2014

ec2-50-18-211-52.us-west-1.compute.amazonaws.com
March 3, 2014

File downloads found at URLs served by arabyads.go2cloud.org.

The following 3 files have been seen to comunicate with arabyads.go2cloud.org in live environments.

URL:
http://arabyads.go2cloud.org/

Network:
Amazon Web Services (AWS), running an EC2 instance

SSL certificate subject:
CN=*.go2cloud.org, OU=Domain Control Validated

SSL certificate issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc."

Web server:
nginx/1.7.9

Facebook:
Shares:  8

Statistics are for the previous month.