repository.ags.gwsrv.com

Goldbet

Domain Information

The domain repository.ags.gwsrv.com registered by Goldbet was initially registered in June of 2012 through Network Solutions, LLC. Currently this domain has been known to host various forms of malware. The hosted servers are located in Hall In Tirol, Tirol within Austria which resides on the RIPE Network Coordination Centre network.
Registrar:
Network Solutions, LLC

Server location:
Tirol, Austria (AT)

Create date:
Monday, June 4, 2012

Expires date:
Sunday, June 4, 2017

Updated date:
Friday, June 3, 2016

ASN:
AS34347 CNH-AS Stadtwerke Hall in Tirol GmbH,AT

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Bkav FE
W32.FamVT.ExpiroPC.PE
100.00%

Total Defense
Win32/Expiro.AK
100.00%

MicroWorld eScan
Win32.Expiro.Gen.2
100.00%

nProtect
Win32.Expiro.Gen.2
100.00%

Quick Heal
W32.Expiro.AX
100.00%

VIPRE Antivirus
Virus.Win32.Expiro.gen.a
100.00%

K7 AntiVirus
Virus
100.00%

Arcabit
Win32.Expiro.Gen.2
100.00%

Baidu Antivirus
Win32.Virus.Expiro
100.00%

F-Prot
W32/Expiro.BC
100.00%

ESET NOD32
Win32/Expiro.NBQ
100.00%

Trend Micro House Call
PE_EXPIRO.JX
100.00%

avast!
Win32:Xpirat
100.00%

Kaspersky
Virus.Win32.Expiro
100.00%

Bitdefender
Win32.Expiro.Gen.2
100.00%

The domain repository.ags.gwsrv.com has been seen to resolve to the following IP address.

July 27, 2016

File downloads found at URLs served by repository.ags.gwsrv.com.

37 / 68    (Infected)
https://repository.ags.gwsrv.com/.../setup.exe  (5a0373a0531a9d84fd6dba44acccff9f)

URL:
http://repository.ags.gwsrv.com/

SSL certificate subject:
CN=*.ags.gwsrv.com, OU=EssentialSSL Wildcard, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
Microsoft-IIS/8.5 (ASP.NET)