girlsgame123.ru

Private Person  (Proxy Registrant)

Domain Information

The domain girlsgame123.ru is registered by proxy through RU-CENTER-RU and was originally registered in February of 2016. Currently this domain has been known to host various forms of malware. The hosted servers are located in Frankfurt Am Main, Hessen within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
RU-CENTER-RU

Server location:
Hessen, Germany (DE)

Create date:
Friday, February 26, 2016

Expires date:
Sunday, February 26, 2017

ASN:
AS3223 VOXILITY , RO

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Trojan.GenericKD.1873114
100.00%

nProtect
Trojan.GenericKD.1873114
100.00%

McAfee
Artemis!3D687F274882
100.00%

Arcabit
Trojan.Generic.D1C94DA
100.00%

avast!
BV:Deleter-EA [Trj]
100.00%

Bitdefender
Trojan.GenericKD.1873114
100.00%

Lavasoft Ad-Aware
Trojan.GenericKD.1873114
100.00%

Emsisoft Anti-Malware
Trojan.GenericKD.1873114
100.00%

Comodo Security
UnclassifiedMalware
100.00%

F-Secure
Trojan.GenericKD.1873114
100.00%

Dr.Web
Trojan.Hosts.33902
100.00%

VIPRE Antivirus
Trojan.Win32.Generic
100.00%

ViRobot
Trojan.Win32.S.Agent.3606211[h]
100.00%

G Data
Trojan.GenericKD.1873114
100.00%

ESET NOD32
BAT/HostsChanger.A potentially unsafe
100.00%

The domain girlsgame123.ru has been seen to resolve to the following IP address.

lh27045.voxility.net
May 17, 2016

File downloads found at URLs served by girlsgame123.ru.

17 / 68    (Malware)
http://girlsgame123.ru/1410334071f/.../cntnt  (minecraft-1.7.2-v0.7.3.exe)

URL:
http://girlsgame123.ru/

Title:
“girlsgame123.ru”

Web server:
nginx/1.9.6 (PHP/5.4.45-1~dotdeb+7.1)