The domain moywot.ru is registered by proxy through R01-RU and was originally registered in March of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Gunzenhausen, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrant:
Private Person
Server location:
Bayern, Germany (DE)
Create date:
Monday, March 25, 2013
Expires date:
Friday, March 25, 2016
ASN:
AS24940 HETZNER-AS Hetzner Online AG,DE
Scanner detections:
Detections (84% detected)
Scan engine
Details
Detections
Kaspersky
UDS:DangerousObject.Multi.Generic, not-a-virus:HEUR:Downloader.NSIS.SoftBase, not-a-virus:Downloader.NSIS.SoftBase
66.67%
ESET NOD32
Win32/Softobase.C potentially unwanted, Win32/InstallCore.CU (variant)
55.56%
Trend Micro House Call
Suspicious_GEN.F47V0220, Suspicious_GEN.F47V0327, Suspicious_GEN.F47V0319, Suspicious_GEN.F47V0128, TROJ_GEN.R021H07EL15, Suspicious_GEN.F47V0315, TROJ_GEN.R047H07DG15, Suspicious_GEN.F47V0316
40.74%
Reason Heuristics
Threat.Win.Reputation.IMP, Adware.Generic.AT (M), PUP.InstallCore.ENG (M)
37.04%
Baidu Antivirus
PUA.Win32.Softobase
37.04%
Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h, Downware.InstallCore
33.33%
Dr.Web
Adware.Downware.9858, Detection.Undefined, Adware.InstallCore.133, Adware.Downware.9855, Adware.Downware.10974, Adware.Downware.10038
29.63%
McAfee
Artemis!C0F96F8D8389, Artemis!F823C509D0A9, Artemis!B8608A909B25, Artemis!4D237E7FEAE4, Artemis!C2C9D49753D6, Artemis!B64EB63AB0AF
29.63%
Sophos
Generic PUA EH (PUA), PUA 'Softobase', Install Core Click run software, Generic PUA PH (PUA), Generic PUA II (PUA)
25.93%
avast!
Win32:Malware-gen, Win32:Rootkit-gen [Rtk], Win32:Adware-gen [Adw]
18.52%
NANO AntiVirus
Trojan.Nsis.SoftBase.dsgvph
18.52%
Panda Antivirus
Generic Suspicious, Trj/CI.A
18.52%
ESET NOD32
Win32/Softobase.C potentially unwanted application
18.52%
K7 AntiVirus
Adware , Unwanted-Program
14.81%
Qihoo 360 Security
HEUR/QVM20.1.Malware.Gen
14.81%
The domain moywot.ru has been seen to resolve to the following 9 IP addresses.
expirepages-kiae-2.nic.ru
April 8, 2016
expirepages-kiae-1.nic.ru
April 8, 2016
static.33.24.243.136.clients.your-server.de
November 7, 2015
static.85-10-196-94.clients.your-server.de
May 6, 2015
85-10-200-21.clients.your-server.de
May 6, 2015
static.158.40.63.178.clients.your-server.de
May 6, 2015
static.113.69.4.46.clients.your-server.de
March 12, 2015
static.140.40.63.178.clients.your-server.de
March 12, 2015
static.182.65.46.78.clients.your-server.de
March 12, 2015
File downloads found at URLs served by moywot.ru.
The following 22 files have been seen to comunicate with moywot.ru in live environments.
Title:
“MoyWOT.ru - все для World of Tanks”
Description:
“Моды и прицелы для World of Tanks - cкины, шкурки, зоны пробития, xvm оленеметр для wot.”
Statistics above are for the previous month of October 2024.