goodgrab.xyz

Domain Information

Server location:
Oregon, United States (US)

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Scanner detections:
Malware distribution  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP
94.00%

avast!
Win32:Oncer, Win32:FakeDownload-G [PUP], Win32:MultiPlug-ABZ [PUP]
6.00%

AVG
Win32/Chir.B@mm, Adware Generic_r.AAD, Adware Generic6.SSW
6.00%

Dr.Web
Trojan.DownLoader12.35055, Trojan.DownLoader12.35266
4.00%

VIPRE Antivirus
Threat.4672667
2.00%

F-Secure
Win32.Runouce.B@mm
2.00%

F-Prot
W32/Thecid.B@mm
2.00%

Emsisoft Anti-Malware
Win32.Runouce.B@mm
2.00%

Microsoft Security Essentials
Threat.Undefined
2.00%

McAfee
Program.MultiPlug-FWG
2.00%

ESET NOD32
Win32/Chir.B virus
2.00%

Norman
Win32.Runouce.B@mm
2.00%

Kaspersky
Email-Worm.Win32.Runouce
2.00%

Sophos
PUA 'MultiPlug' (of type Adware)
2.00%

The domain goodgrab.xyz has been seen to resolve to the following 6 IP addresses.

June 7, 2016

192.193.28.185.gransy.com
June 7, 2016

June 2, 2016

ec2-52-11-167-137.us-west-2.compute.amazonaws.com
June 30, 2015

ec2-52-27-23-115.us-west-2.compute.amazonaws.com
June 30, 2015

ec2-54-200-195-191.us-west-2.compute.amazonaws.com
May 2, 2015

File downloads found at URLs served by goodgrab.xyz.

 
Latest 30 of 114 download URLs

The following 22 files have been seen to comunicate with goodgrab.xyz in live environments.

 
Latest 20 of 22 files