marmosinte.sslblindado.com

Universo Online SA

Domain Information

The domain marmosinte.sslblindado.com registered by Universo Online SA was initially registered in November of 2007 through GODADDY.COM, LLC. Currently this domain has been known to host various forms of malware. The hosted servers are located in Sao Paulo, Sao Paulo within Brazil which resides on the Latin American and Caribbean IP address Regional Registry network.
Registrar:
GODADDY.COM, LLC

Server location:
Sao Paulo, Brazil (BR)

Create date:
Friday, November 16, 2007

Expires date:
Wednesday, November 16, 2016

Updated date:
Saturday, July 25, 2015

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Emsisoft Anti-Malware
Gen:Variant.Strictor.80021
100.00%

F-Secure
Gen:Variant.Strictor.80021
100.00%

Lavasoft Ad-Aware
Gen:Variant.Strictor.80021
100.00%

ESET NOD32
MSIL/TrojanDownloader.Agent.BGK trojan
100.00%

Norman
Gen:Variant.Strictor.80021
100.00%

MicroWorld eScan
Gen:Variant.Strictor.80021
100.00%

Arcabit
Trojan.Strictor.D13895
100.00%

Bitdefender
Gen:Variant.Strictor.80021
100.00%

Avira AntiVirus
TR/Dropper.MSIL.235808
100.00%

G Data
Gen:Variant.Strictor.80021
100.00%

Baidu Antivirus
Trojan.MSIL.Agent
100.00%

Fortinet FortiGate
MSIL/Agent.BGK!tr.dldr
100.00%

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
100.00%

The domain marmosinte.sslblindado.com has been seen to resolve to the following IP address.

April 12, 2016

File downloads found at URLs served by marmosinte.sslblindado.com.

13 / 68    (Malware)

URL:
http://marmosinte.sslblindado.com/

SSL certificate subject:
CN=*.sslblindado.com, O=Universo Online SA, L=Sao Paulo, S=Sao Paulo, C=BR

SSL certificate issuer:
CN=GeoTrust SHA256 SSL CA, O=GeoTrust Inc., C=US

Web server:
nginx