getgsafe.me

WhoisGuard, Inc.  (Proxy Registrant)

Domain Information

The domain getgsafe.me is registered by proxy through eNom Inc R32-ME (48) and was originally registered in October of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Reykjavik, Hofuoborgarsvaoio within IS which resides on the RIPE Network Coordination Centre network.
Registrar:
eNom Inc R32-ME (48)

Server location:
Hofuoborgarsvaoio, IS (IS)

Create date:
Wednesday, October 22, 2014

Expires date:
Saturday, October 22, 2016

Updated date:
Tuesday, September 22, 2015

ASN:
AS50613 THORDC-AS THOR Data Center ehf,IS

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.BR Software, Threat.BR Software.Installer, PUP.BR Software.GENCOLABS.Installer (M), PUP.BR Software.GENCOLAB.Installer (M), PUP.BR Software (M)
100.00%

McAfee
Artemis!B6F079BE1209, Artemis!4806D862A6C3
8.70%

F-Prot
W32/A-07794f8f
8.70%

Trend Micro House Call
Suspicious_GEN.F47V1116, Suspicious_GEN.F47V1216
8.70%

VIPRE Antivirus
Trojan.Win32.Generic
4.35%

Norman
Downloader
4.35%

Sophos
Mal/Generic-S
4.35%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
4.35%

AVG
Generic
4.35%

MicroWorld eScan
Trojan.Generic.12366387
4.35%

NANO AntiVirus
Trojan.Win32.Triosir.dgibtv
4.35%

avast!
Win32:Malware-gen
4.35%

Bitdefender
Trojan.Generic.12366387
4.35%

Lavasoft Ad-Aware
Trojan.Generic.12366387
4.35%

F-Secure
Trojan.Generic.12366387
4.35%

The domain getgsafe.me has been seen to resolve to the following 2 IP addresses.

May 22, 2016

February 12, 2016

File downloads found at URLs served by getgsafe.me.

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (ac45ff5dbe6b1b0f9819b78e834346f2)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (789da62f9f83172f8110ce0ea0b1de3f)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (3fb2dfa1601c2c9aa1e0c9d60be20d7f)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (7653f8702a4a09ad1a7c1b54bf50af3d)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (e866dc6932b4a9831be71e3c224519f4)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (2d141993efb01bf115721cd6890c28e2)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (ba10f70091734eb34eeee35d9f2534a5)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (bdf22e867ed5642eaca269df3d8b87ff)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (abb751a7abd7ce5364d3df07065c06d2)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (b7fffe7bf3b3b2e1254d1da30056765c)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (c77940a431a8551da18d531eaca3fb3e)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (490a8fe1179c0ebf5ed9cf9be6f45fcd)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (1972ac7a935a29aa6be5e59c3cfadedb)

14 / 68    (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (4806d862a6c3ca33cf5548ccbe912e92)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (5c3976b7f83a63852d5d5cd3c2059ed8)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (281064e8484e93d48901fad61f089c99)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (4e06b4ee1b47c370bbc5a3ebbe157ee9)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (e93b2d1b9018e0dabf228ac902f2c587)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (3385529db0a22a8b3b5560f7e7d43c0e)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (609b7d645835efa65b3d721d90d1a377)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (3673642797f69cea223138d1ab99b1d0)

1 / 68      (Adware)
http://getgsafe.me/.../setup_premium_hdtv2.exe  (a1c308cead16cefba970b3652e4ea547)

9 / 68      (Adware)
http://getgsafe.me/.../gsafe.exe  (b6f079be120993d11a08a472b4e42c9d)

URL:
http://getgsafe.me/

Web server:
nginx/1.0.15

30 of 44 related domains