ext.ghokswa.com

Bao Yu

Domain Information

The domain ext.ghokswa.com registered by Bao Yu was initially registered in May of 2015 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Seattle, Washington within the United States which resides on the Akamai Technologies, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Washington, United States (US)

Create date:
Wednesday, May 27, 2015

Expires date:
Saturday, May 27, 2017

Updated date:
Thursday, November 5, 2015

ASN:
AS20940 AKAMAI-ASN1 Akamai International B.V.,US

Root domain:

Scanner detections:
Detections  (86% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Zhang.YupengZh.Meta (M), Trojan.Ghoksaw (M), PUP.Elex.ShanFeng (M), Adware.IHeeaWA (M)
100.00%

The domain ext.ghokswa.com has been seen to resolve to the following 25 IP addresses.

a184-51-126-34.deploy.static.akamaitechnologies.com
May 20, 2016

a184-51-126-11.deploy.static.akamaitechnologies.com
May 20, 2016

a104-96-220-249.deploy.static.akamaitechnologies.com
May 18, 2016

a104-112-235-10.deploy.static.akamaitechnologies.com
May 18, 2016

a23-220-148-34.deploy.static.akamaitechnologies.com
April 12, 2016

a23-220-148-19.deploy.static.akamaitechnologies.com
April 12, 2016

a23-220-148-10.deploy.static.akamaitechnologies.com
April 12, 2016

a23-220-148-66.deploy.static.akamaitechnologies.com
April 12, 2016

a23-220-148-33.deploy.static.akamaitechnologies.com
February 27, 2016

a23-220-148-8.deploy.static.akamaitechnologies.com
February 27, 2016

a23-220-148-51.deploy.static.akamaitechnologies.com
February 27, 2016

a23-220-148-49.deploy.static.akamaitechnologies.com
February 27, 2016

a23-220-148-43.deploy.static.akamaitechnologies.com
February 27, 2016

a184-51-126-106.deploy.static.akamaitechnologies.com
February 20, 2016

a184-51-126-83.deploy.static.akamaitechnologies.com
February 20, 2016

February 18, 2016

February 18, 2016

February 17, 2016

February 17, 2016

a23-220-148-25.deploy.static.akamaitechnologies.com
February 4, 2016

a23-220-148-41.deploy.static.akamaitechnologies.com
February 4, 2016

a23-15-7-146.deploy.static.akamaitechnologies.com
February 1, 2016

a23-15-7-113.deploy.static.akamaitechnologies.com
February 1, 2016

a23-0-160-18.deploy.static.akamaitechnologies.com
February 1, 2016

a23-0-160-83.deploy.static.akamaitechnologies.com
February 1, 2016

File downloads found at URLs served by ext.ghokswa.com.

0 / 68
http://ext.ghokswa.com/gour/.../TRun.dll  (af35f927350dbe3cff51c764dc947b99)

1 / 68      (PUP)
http://ext.ghokswa.com/gour/.../activehhh.dll  (0db675567e9938441bd8d9c961fc4b43)

1 / 68      (PUP)
http://ext.ghokswa.com/gour/.../hhhhsetacti.dll  (83fb126df097e5b069fd6f00fc9b7e8b)

0 / 68
http://ext.ghokswa.com/gour/.../TestRun.dll  (64226d66f098e2a31d6ec3e983866cd5)

1 / 68      (PUP)
http://ext.ghokswa.com/gour/.../fix_repeat.dll  (df11019d472d5b41279797607521e337)

1 / 68      (Malware)
http://ext.ghokswa.com/gour/.../facebook.dll  (5749bef8d6b2b2f19139ae0510e1fc9f)

1 / 68      (Malware)
http://ext.ghokswa.com/gour/.../ActiveRun.dll  (785739e7ffcde39a48dc941fdd505e6b)

1 / 68      (Malware)
http://ext.ghokswa.com/gour/.../yesforsearches.dll  (bf22cae88a67c5168cea455b3730d951)

1 / 68      (PUP)
http://ext.ghokswa.com/gour/.../CloudRun_21.dll  (25b52f043719976feeeed143120b7326)

1 / 68      (Malware)
http://ext.ghokswa.com/gour/.../cloudabcd.dll  (aceb79a3642b74b63894f51cf9968174)

1 / 68      (Malware)
http://ext.ghokswa.com/gour/.../yesforsearches.dll  (c0800436e885e2175bd2a8df79fc1afa)

1 / 68      (PUP)

1 / 68      (PUP)
http://ext.ghokswa.com/gour/.../CloudRun_net_ABtest.dll  (4f91f2767ea26fad011d409f8f6673c3)

1 / 68      (PUP)
http://ext.ghokswa.com/gour/.../cloud_webdata.dll  (aa1100c3b3e3f9a05845486a6745eac4)

The following 172 files have been seen to comunicate with ext.ghokswa.com in live environments.

 
Latest 20 of 181 files

URL:
http://ext.ghokswa.com/

Web server:
nginx/0.7.67