The domain go.goforfiles.com registered by Righway Technologies, Inc. was initially registered in August of 2012 through INTERNET.BS CORP.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
INTERNET DOMAIN SERVICE BS CORP
Northern Ireland, United Kingdom (GB)
Thursday, August 16, 2012
Tuesday, August 16, 2016
Friday, December 11, 2015
Detections (100% detected)
PUP.RighwayTechnologies.?, PUP.RighwayTechnologies.Q, PUP.RighwayTechnologies.FF, PUP.RighwayTechnologies.e, PUP.RighwayTechnologies.P, PUP.RighwayTechnologies.X, PUP.RighwayTechnologies.J, PUP.RighwayTechnologies.m, PUP.Via Advertising.RighwayTechnologies.Bundler (M)
Win32/YourFileDownloader (variant), Win32/ExpressFiles (variant)
ExpressFiles Installer, Yontoo, Threat.4783941
Go For Files, PUA 'Go For Files'
Trend Micro House Call
TROJ_SPNR.08B713, TROJ_GEN.F47V1114, TROJ_SPNR.28B713, TROJ_SPNR.08BB13, TROJ_GEN.F47V0430, TROJ_GEN.F47V0607, HV_ZYX_BL1329AD.TOMC, TROJ_GEN.F47V1022
AhnLab V3 Security
Adware.Downware.825, Adware.Downware.914, Tool.DownLoader.52, Adware.Downware.747
Win32:PUP-gen [PUP], Win32:Expressfiles-A [PUP]
TROJ_SPNR.08B713, TROJ_SPNR.28B713, TROJ_SPNR.08BB13, TROJ_SPNR.08BK13
Artemis!07343314F7B4, Artemis!9294A626096D, Artemis!DF3B28428CBF, Artemis!332D3639F52B, Artemis!3AC8BEB60DCF, Artemis!392EE4F35BC6, Artemis!26628FEC66EE
McAfee Web Gateway
Artemis!07343314F7B4, Artemis!9294A626096D, Artemis!DF3B28428CBF, Artemis!332D3639F52B, Artemis!3AC8BEB60DCF, Artemis!392EE4F35BC6
MalSign.Righway Technologies, Skodna.Generic_r, Dropper.Generic9
K7 Gateway Antivirus
The domain go.goforfiles.com has been seen to resolve to the following 5 IP addresses.
May 4, 2015
December 22, 2013
December 22, 2013
File downloads found at URLs served by go.goforfiles.com.
Latest 30 of 45 download URLs
The following 137 files have been seen to comunicate with go.goforfiles.com in live environments.
Statistics are for the previous month.