gfg4.info

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain gfg4.info is registered by proxy through GoDaddy.com, LLC (R171-LRMS). This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the iWeb Technologies Inc. network.
Registrar:
GoDaddy.com, LLC (R171-LRMS)

Server location:
Quebec, Canada (CA)

ASN:
AS32613 IWEB-AS - iWeb Technologies Inc.,CA

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.3DIBTechnologies.m, PUP.Installer.3DIBTechnologies.q, PUP.Installer.3DIBTechnologies.p
100.00%

VIPRE Antivirus
Marketscore.RelevantKnowledge, Threat.4786236
50.00%

Dr.Web
Adware.Downware.2527
37.50%

Avira AntiVirus
APPL/Downloader.Gen9
25.00%

Trend Micro House Call
TROJ_GEN.F47V0108
12.50%

The domain gfg4.info has been seen to resolve to the following IP address.

3dib.com
September 2, 2014

File downloads found at URLs served by gfg4.info.

4 / 68      (Adware)
http://gfg4.info/.../download?id=5304f96ee85ba&cid=530fbe6f821f8738760331  (flappy bird setup%ch_530fbe6f821f8738760331_.exe)

3 / 68      (Adware)
http://gfg4.info/.../download?id=51bf41b5ebedb&cid=5312aa3c8e36c026380406  (candy crush setup%ch_5312aa3c8e36c026380406_.exe)

4 / 68      (Adware)
http://gfg4.info/.../download?id=5303cc1072a12&cid=5312ae2158ee8647239307  (flappy bird setup%ch_5312ae2158ee8647239307_.exe)

3 / 68      (Adware)
http://gfg4.info/.../download?id=525ed14b76e33&cid=52ce2cd96c657630891331  (minion rush setup%ch_52ce2cd96c657630891331_.exe)

1 / 68      (Adware)
http://gfg4.info/.../download?id=51bf41b5ebedb&cid=537aa7d817225013044288  (candy crush setup%ch_537aa7d817225013044288_.exe)

1 / 68      (Adware)
http://gfg4.info/.../download?id=51e564bd169cd&cid=537aa77eae024850677695  (deal or no deal setup%ch_537aa77eae024850677695_.exe)

1 / 68      (Adware)
http://gfg4.info/.../download?id=525ed14b76e33&cid=537aa6c5340ab881512396  (minion rush setup%ch_537aa6c5340ab881512396_.exe)

1 / 68      (Adware)
http://gfg4.info/.../download?id=51dad747e11e8&cid=537aa2de2418c745046828  (subway surfers setup%ch_537aa2de2418c745046828_.exe)

URL:
http://gfg4.info/

Web server:
Apache/2.2.21 (Unix) mod_ssl/2.2.21 OpenSSL/0.9.8e-fips-rhel5 DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 (PHP/5.3.9)