The domain dn.goforfiles.com registered by Righway Technologies, Inc. was initially registered in August of 2012 through INTERNET.BS CORP.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
INTERNET DOMAIN SERVICE BS CORP
Northern Ireland, United Kingdom (GB)
Thursday, August 16, 2012
Tuesday, August 16, 2016
Friday, December 11, 2015
Detections (100% detected)
PUP.RighwayTechnologies.c, PUP.RighwayTechnologies.k, PUP.RighwayTechnologies.j, PUP.RighwayTechnologies.Q, PUP.RighwayTechnologies.R, PUP.RighwayTechnologies.?, PUP.RighwayTechnologies.S, PUP.RighwayTechnologies.s, PUP.RighwayTechnologies.W, Threat.Win.Reputation.IMP
Go For Files, PUA 'Go For Files'
Win32/ExpressDownloader (variant), Win32/YourFileDownloader (variant), Win32/ExpressDownloader.H potentially unwanted (variant)
ExpressFiles Installer, Yontoo, Threat.4925438
Trend Micro House Call
TROJ_GEN.F47V0607, TROJ_GEN.F47V0920, TROJ_GEN.F47V0827, TROJ_GEN.F47V0412, TROJ_GEN.F47V0430, TROJ_GEN.F47V0531, TROJ_GEN.F47V0529
Artemis!DF3B28428CBF, Artemis!34E7AF27DB6D, Artemis!767228F5C58C, Artemis!FD3BB23E84E6, Artemis!7B998F57FCBC, Artemis!75828DD12967, Artemis!1DD42C91BE13, Artemis!C452BBCA28D5, Artemis!301B31FB93A0, Artemis!3D677BB78DE7
McAfee Web Gateway
Artemis!DF3B28428CBF, Artemis!34E7AF27DB6D, Artemis!767228F5C58C, Artemis!FD3BB23E84E6, Artemis!7B998F57FCBC, Artemis!75828DD12967
K7 Gateway Antivirus
AhnLab V3 Security
Skodna.Generic_r, Dropper.Generic9, Righway Technologies
Win32:PUP-gen [PUP], Win32:Malware-gen, Win32:Adware-gen [Adw]
AdWare.Win32.YourFileDownloader, not-a-virus:Downloader.Win32.Agent, PUA.Expressdownloader
The domain dn.goforfiles.com has been seen to resolve to the following 3 IP addresses.
May 3, 2015
May 23, 2014
File downloads found at URLs served by dn.goforfiles.com.
Latest 30 of 242 download URLs
The following 137 files have been seen to comunicate with dn.goforfiles.com in live environments.