optcfuxqe5zglxobngffqb0dt1lm5wux.sistema.financeiro.cobfinanceira.com

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain optcfuxqe5zglxobngffqb0dt1lm5wux.sistema.financeiro.cobfinanceira.com is registered by proxy through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM and was originally registered in November of 2015. Currently this domain has been known to host various forms of malware. The hosted servers are located in Tampa, Florida within the United States which resides on the Voodoo.com, Inc network.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Florida, United States (US)

Create date:
Friday, November 13, 2015

Expires date:
Sunday, November 13, 2016

Updated date:
Saturday, November 14, 2015

ASN:
AS19867 VOODOO1 - Voodoo.com, Inc,US

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Gen:Variant.Kazy.782732
100.00%

McAfee
Artemis!375828C373DF
100.00%

Bitdefender
Gen:Variant.Kazy.782732
100.00%

K7 AntiVirus
Trojan-Downloader
100.00%

Arcabit
Trojan.Kazy.DBF18C
100.00%

ESET NOD32
MSIL/TrojanDownloader.Agent.BMO (variant)
100.00%

avast!
Win32:Malware-gen
100.00%

Kaspersky
HEUR:Trojan.Win32.Generic
100.00%

Lavasoft Ad-Aware
Gen:Variant.Kazy.782732
100.00%

Emsisoft Anti-Malware
Gen:Variant.Kazy.782732
100.00%

F-Secure
Gen:Variant.Kazy.782732
100.00%

VIPRE Antivirus
Trojan.Win32.Generic
100.00%

Trend Micro
TROJ_GEN.R047C0DBJ16
100.00%

Sophos
Mal/Generic-S
100.00%

Avira AntiVirus
TR/Dropper.MSIL.262521
100.00%

The domain optcfuxqe5zglxobngffqb0dt1lm5wux.sistema.financeiro.cobfinanceira.com has been seen to resolve to the following IP address.

192.64.147.142.voodoo.com
August 10, 2016

File downloads found at URLs served by optcfuxqe5zglxobngffqb0dt1lm5wux.sistema.financeiro.cobfinanceira.com.

URL:
http://optcfuxqe5zglxobngffqb0dt1lm5wux.sistema.financeiro.cobfinanceira.com/

Web server:
Apache (PHP/5.3.8)