go.goforfiles.com

Righway Technologies, Inc.

Domain Information

The domain go.goforfiles.com registered by Righway Technologies, Inc. was initially registered in August of 2012 through INTERNET.BS CORP.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Remove Malware from go.goforfiles.com - Powered by Reason Core Security
Registrar:
INTERNET DOMAIN SERVICE BS CORP

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Thursday, August 16, 2012

Expires date:
Tuesday, August 16, 2016

Updated date:
Friday, December 11, 2015

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.RighwayTechnologies.?, PUP.RighwayTechnologies.Q, PUP.RighwayTechnologies.FF, PUP.RighwayTechnologies.e, PUP.RighwayTechnologies.P, PUP.RighwayTechnologies.X, PUP.RighwayTechnologies.J, PUP.RighwayTechnologies.m, PUP.Via Advertising.RighwayTechnologies.Bundler (M)
100.00%

ESET NOD32
Win32/YourFileDownloader (variant), Win32/ExpressFiles (variant)
92.59%

VIPRE Antivirus
ExpressFiles Installer, Yontoo, Threat.4783941
88.89%

Malwarebytes
PUP.Optional.GoForFiles.A
81.48%

Sophos
Go For Files, PUA 'Go For Files'
74.07%

Trend Micro House Call
TROJ_SPNR.08B713, TROJ_GEN.F47V1114, TROJ_SPNR.28B713, TROJ_SPNR.08BB13, TROJ_GEN.F47V0430, TROJ_GEN.F47V0607, HV_ZYX_BL1329AD.TOMC, TROJ_GEN.F47V1022
55.56%

AhnLab V3 Security
PUP/Win32.ExpressFiles
55.56%

Dr.Web
Adware.Downware.825, Adware.Downware.914, Tool.DownLoader.52, Adware.Downware.747
55.56%

avast!
Win32:PUP-gen [PUP], Win32:Expressfiles-A [PUP]
55.56%

Trend Micro
TROJ_SPNR.08B713, TROJ_SPNR.28B713, TROJ_SPNR.08BB13, TROJ_SPNR.08BK13
48.15%

McAfee
Artemis!07343314F7B4, Artemis!9294A626096D, Artemis!DF3B28428CBF, Artemis!332D3639F52B, Artemis!3AC8BEB60DCF, Artemis!392EE4F35BC6, Artemis!26628FEC66EE
48.15%

McAfee Web Gateway
Artemis!07343314F7B4, Artemis!9294A626096D, Artemis!DF3B28428CBF, Artemis!332D3639F52B, Artemis!3AC8BEB60DCF, Artemis!392EE4F35BC6
48.15%

AVG
MalSign.Righway Technologies, Skodna.Generic_r, Dropper.Generic9
48.15%

K7 Gateway Antivirus
Unwanted-Program
44.44%

K7 AntiVirus
Unwanted-Program
44.44%

The domain go.goforfiles.com has been seen to resolve to the following 5 IP addresses.

unallocated.barefruit.co.uk
May 4, 2015

October 9, 2014

May 30, 2014

mail.goforfiles.com
December 22, 2013

199.195.196.182.static.midphase.com
December 22, 2013

File downloads found at URLs served by go.goforfiles.com.

25 / 68    (Adware)

1 / 68      (Adware)

14 / 68    (Adware)

12 / 68    (Adware)
http://go.goforfiles.com/j5GXVmTR6XZ/lJ5LZcqoZXnRvCMv9ul/.../BVg==  (bmw_etk_local_windows_7_64_bit_downloader_415.exe)

9 / 68      (Adware)
http://go.goforfiles.com/.../oYOR7jIUQLV3xhDhooCU4w8RQ7Z  (cardscan_600c_driver_download_downloader_605.exe)

8 / 68      (Adware)
http://go.goforfiles.com/.../1n1GIA==  (metodo_silva_de_controle_mental.zip_downloader.exe)

16 / 68    (Adware)
http://go.goforfiles.com/j5HgBETU7AhCjIdvPoqDBziaoTQv8ep LvftdyL40HVpoYwzH bZbgCnmD1dtZgHE XMVwXY  (mémoires_de_nos_pères_dvdrip_vf_vostfr_mkv_downloader_99080.exe)

42 / 68    (Adware)

3 / 68      (Adware)
http://go.goforfiles.com/.../AXwfQyk1BiZQLB9oxRxifcBU1nWAfe8Y=  (paramahansa_yogananda_el_amante_cosmico_downloader_2.exe)

14 / 68    (Adware)
http://go.goforfiles.com/.../  (slp.myegy.mr._hmed.rmvb_downloader_99122.exe)

5 / 68      (Adware)
http://go.goforfiles.com/.../9BnG bcahPmyyhHsZVeHOzAQUGVmxxbjZlSHJw8FQ==  (krug_tarnen_tricksen_taeuschen.pdf_downloader.exe)

26 / 68    (Adware)
http://go.goforfiles.com/.../oYOR7jIVQLW3xhDhooCU4w8QQ==  (gangnam_style_sheet_music.pdf_downloader_2.exe)

5 / 68      (Adware)
http://go.goforfiles.com/.../wQ==  (krug_tarnen_tricksen_taeuschen.pdf_downloader.exe)

2 / 68      (Adware)
http://go.goforfiles.com/j5GxX2edv1prxKRNb5W1Km/.../qCCluExFkG1dscT4p2HleIOEY=  (the-vampire-diaries-s04e10-vostfr_downloader_1.exe)

 
Latest 30 of 45 download URLs

The following 137 files have been seen to comunicate with go.goforfiles.com in live environments.

 
Latest 20 of 137 files

Facebook:
Likes:  96
Shares:  507
Comments:  125

Statistics are for the previous month.

Remove Malware from go.goforfiles.com - Powered by Reason Core Security