Googlescan.ru

By GoldSparrow in Browser Hijackers

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 7
First Seen: April 21, 2017
Last Seen: September 6, 2021
OS(es) Affected: Windows

The Googlescan.ru domain is deemed as untrusted because it is related to a browser hijacker and phishing portals that are clones of icloud.com, which is the iCloud platform by Apple Inc. The Googlescan.ru site is presented to users as a search service that is powered by a customized Google engine. However, the custom search at Googlescan.ru may redirect users to phishing pages and limit their searches to a defined list of sites. We have found that the browser hijacker associated with Googlescan.ru is aimed at Web surfers based in Russia. The Googlescan.ru browser hijacker may travel in the company of free programs like AIMP3 and Light Alloy Player that are developed by teams of Russian programmers. The Googlescan.ru browser hijacker may run as a background app and change your settings in Google Chrome, Yandex Browser and Mozilla Firefox. The app is programmed to redirect users to Googlescan.ru and set Googlescan.ru as their search provider, default new tab and start page.

The Googlescan.ru site does not have a publicly known owner. A network analysis unveiled that the operator of Googlescan.ru claims marketing revenue from the Google DoubleClick and Yandex Advertisements by embedding commercials on Googlescan.ru. Sites like Googlescan.ru are easy to set up, and its owner is estimated to earn 65 USD on a daily basis since reports from services like Hypestat.com show that there are twenty thousand unique visits each day. We do not recommend users taking advantage of Googlescan.ru because the service is known to push pop-up windows loaded with marketing materials and may redirect users to the following domains:

  • icloudeu[.]com
  • cloudru[.]info
  • icloud-rus[.]com

These pages are registered to the same IP address as Googlescan.ru and appear to be clones of icloud.com that is the legitimate access portal for the Apple's online storage platform. Computer users that enter their log-in credentials on the pages listed above may fall victim to an account hijacking. If you are redirected to Googlescan.ru and your browser prevents your from closing pop-up messages at Googlescan.ru you may be infected with a browser hijacker. PC security experts advise the removal of riskware and browser hijackers to be performed with a reliable security instrument that is proven to clean such apps.

URLs

Googlescan.ru may call the following URLs:

googlescan.ru

Trending

Most Viewed

Loading...