converter.gomlab.com

Gretech Corp.

Domain Information

The domain converter.gomlab.com registered by Gretech Corp. was initially registered in January of 2008 through GABIA, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Seattle, Washington within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
GABIA, INC.

Server location:
Washington, United States (US)

Create date:
Tuesday, January 22, 2008

Expires date:
Sunday, January 22, 2017

Updated date:
Monday, December 7, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (67% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.GRETECH.GretechC.Installer.Meta (L), PUP.Gretech.GretechC.Installer.Meta (L)
83.33%

ESET NOD32
Win32/OpenCandy potentially unsafe application
16.67%

Dr.Web
Threat.Undefined
16.67%

NANO AntiVirus
Trojan.Win32.OpenCandy.dwzazk
16.67%

F-Prot
W32/OpenCandy.A.gen
16.67%

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5 [F]
16.67%

Zillya! Antivirus
Adware.OpenCandy.Win32.102
16.67%

Avira AntiVirus
PUA/OpenCandy.Gen
16.67%

Fortinet FortiGate
Adware/OpenCandy
16.67%

Arcabit
PUP.Adware.OpenCandy
16.67%

IKARUS anti.virus
PUA.OpenCandy
16.67%

AVG
OpenCandy
16.67%

The domain converter.gomlab.com has been seen to resolve to the following 72 IP addresses.

server-52-84-127-116.iad16.r.cloudfront.net
August 23, 2016

server-52-84-127-56.iad16.r.cloudfront.net
August 23, 2016

server-52-84-127-230.iad16.r.cloudfront.net
August 23, 2016

server-52-84-127-218.iad16.r.cloudfront.net
August 23, 2016

server-52-84-127-201.iad16.r.cloudfront.net
August 23, 2016

server-52-84-127-174.iad16.r.cloudfront.net
August 23, 2016

server-52-84-127-162.iad16.r.cloudfront.net
August 23, 2016

server-52-84-127-126.iad16.r.cloudfront.net
August 23, 2016

server-52-85-147-76.iad12.r.cloudfront.net
August 22, 2016

server-52-85-147-55.iad12.r.cloudfront.net
August 22, 2016

server-52-85-147-45.iad12.r.cloudfront.net
August 22, 2016

server-52-85-147-41.iad12.r.cloudfront.net
August 22, 2016

server-52-85-147-14.iad12.r.cloudfront.net
August 22, 2016

server-52-85-147-228.iad12.r.cloudfront.net
August 22, 2016

server-52-85-147-217.iad12.r.cloudfront.net
August 22, 2016

server-52-85-147-213.iad12.r.cloudfront.net
August 22, 2016

server-54-192-18-97.iad12.r.cloudfront.net
May 25, 2016

server-54-192-18-90.iad12.r.cloudfront.net
May 25, 2016

server-54-192-18-77.iad12.r.cloudfront.net
May 25, 2016

server-54-192-18-75.iad12.r.cloudfront.net
May 25, 2016

server-54-192-18-61.iad12.r.cloudfront.net
May 25, 2016

server-54-192-18-211.iad12.r.cloudfront.net
May 25, 2016

server-54-192-18-138.iad12.r.cloudfront.net
May 25, 2016

server-54-192-18-136.iad12.r.cloudfront.net
May 25, 2016

server-52-85-140-103.iad2.r.cloudfront.net
April 12, 2016

server-52-85-140-86.iad2.r.cloudfront.net
April 12, 2016

server-52-85-140-65.iad2.r.cloudfront.net
April 12, 2016

server-52-85-140-48.iad2.r.cloudfront.net
April 12, 2016

server-52-85-140-243.iad2.r.cloudfront.net
April 12, 2016

server-52-85-140-197.iad2.r.cloudfront.net
April 12, 2016

 
Showing 30 of 72 IP Addresses

File downloads found at URLs served by converter.gomlab.com.

1 / 68      (PUP)

0 / 68
http://converter.gomlab.com/download_log.gom?utype=4  (gomvideoconvertersetup_eng.exe)

1 / 68      (PUP)

1 / 68      (PUP)
http://converter.gomlab.com/download_log.gom?utype=4  (gomvideoconvertersetupeng.exe)

1 / 68      (PUP)
http://converter.gomlab.com/download_log.gom?utype=4  (gomvideoconvertersetup_eng_etc.exe)

0 / 68
http://converter.gomlab.com/download_log.gom?utype=4  (gomvideoconvertersetup_eng.exe)

1 / 68      (PUP)
https://converter.gomlab.com/download_log.gom?utype=4  (gomvideoconvertersetup_www.instalki.pl.exe)

11 / 68    (PUP)
http://converter.gomlab.com/download_log.gom?utype=4  (gomvideoconvertersetup_eng.exe)

0 / 68
http://converter.gomlab.com/download_log.gom?utype=4  (GOMVIDEOCONVERTERSETUP_ENG.EXE)

1 / 68      (PUP)
http://converter.gomlab.com/download_log.gom?utype=4  (gomvideoconvertersetup_www.instalki.pl.exe)

The following 18 files have been seen to comunicate with converter.gomlab.com in live environments.

 
Latest 20 of 27 files

URL:
http://converter.gomlab.com/

Google Analytics:
UA-3555958

Title:
“GOM Video Converter. Enjoy all your videos, any time, anywhere.”

Description:
“GOM Video Converter is a powerful all purpose video conversion software. Developed by the creators of GOM Media Player, it supports a wide variety of input and output formats.”

Network:
Amazon Cloudfront

SSL certificate subject:
CN=*.gomlab.com, OU=Development Team, O=Gretech Corp., L=Gangnam-gu, S=Seoul, C=KR

SSL certificate issuer:
CN=thawte SSL CA - G2, O="thawte, Inc.", C=US

Web server:
Apache

Facebook:
Likes:  1
Shares:  4

Statistics are for the previous month.