servicosdo.sslblindado.com

Universo Online SA

Domain Information

The domain servicosdo.sslblindado.com registered by Universo Online SA was initially registered in November of 2007 through GODADDY.COM, LLC. Currently this domain has been known to host various forms of malware. The hosted servers are located in Sao Paulo, Sao Paulo within Brazil which resides on the Latin American and Caribbean IP address Regional Registry network.
Registrar:
GODADDY.COM, LLC

Server location:
Sao Paulo, Brazil (BR)

Create date:
Friday, November 16, 2007

Expires date:
Wednesday, November 16, 2016

Updated date:
Saturday, July 25, 2015

ASN:
AS7162 Universo Online S.A.,BR

Root domain:

Scanner detections:
Malware distribution  (60% detected)

Scan engine
Details
Detections

Emsisoft Anti-Malware
Gen:Variant.Kazy.773206, Trojan.GenericKD.2973948
90.00%

ESET NOD32
MSIL/TrojanDownloader.Agent.BGK trojan, MSIL/TrojanDownloader.Agent.AHG trojan
70.00%

Norman
Gen:Variant.Kazy.773206
60.00%

MicroWorld eScan
Gen:Variant.Kazy.773206, Trojan.GenericKD.2973948
30.00%

Bitdefender
Gen:Variant.Kazy.773206, Trojan.GenericKD.2973948
30.00%

ESET NOD32
MSIL/TrojanDownloader.Agent.BGK (variant), MSIL/TrojanDownloader.Agent.AHG (variant)
30.00%

F-Secure
Gen:Variant.Kazy.773206, Trojan.GenericKD.2973948
30.00%

Arcabit
Trojan.Kazy.DBCC56, Trojan.Generic.D2D60FC
30.00%

G Data
Gen:Variant.Kazy.773206, Trojan.GenericKD.2973948
30.00%

Fortinet FortiGate
MSIL/Agent.BGK!tr.dldr
30.00%

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
30.00%

Lavasoft Ad-Aware
Gen:Variant.Kazy.773206
30.00%

McAfee
Artemis!2927F8174192, Artemis!C587A3386A55
20.00%

Lavasoft Ad-Aware
Gen:Variant.Kazy.773206
20.00%

Baidu Antivirus
Trojan.MSIL.Agent
20.00%

The domain servicosdo.sslblindado.com has been seen to resolve to the following IP address.

February 10, 2016

File downloads found at URLs served by servicosdo.sslblindado.com.

3 / 68      (inconclusive)

4 / 68      (Malware)

6 / 68      (Malware)

14 / 68    (Malware)

21 / 68    (Malware)
https://servicosdo.sslblindado.com/.../  (cobranca-pdf456834625.exe)

3 / 68      (inconclusive)

1 / 68      (inconclusive)
https://servicosdo.sslblindado.com/.../  (Loader-UZTCPQFWLQ.exe)

5 / 68      (Malware)

3 / 68      (inconclusive)

10 / 68    (Malware)

URL:
http://servicosdo.sslblindado.com/

SSL certificate subject:
CN=*.sslblindado.com, O=Universo Online SA, L=Sao Paulo, S=Sao Paulo, C=BR

SSL certificate issuer:
CN=GeoTrust SHA256 SSL CA, O=GeoTrust Inc., C=US

Web server:
nginx