tibiaiwindbot.com

Whois Data Protection Sp. z o.o.

Domain Information

The domain tibiaiwindbot.com registered by Whois Data Protection Sp. z o.o. was initially registered in January of 2015 through NETART SP Z O.O. Currently this domain has been known to host various forms of malware. The hosted servers are located in Roubaix, Nord-Pas-De-Calais within France which resides on the RIPE Network Coordination Centre network.
Registrar:
NETART SP Z O.O

Server location:
Nord-Pas-De-Calais, France (FR)

Create date:
Wednesday, January 21, 2015

Expires date:
Saturday, January 21, 2017

Updated date:
Friday, January 22, 2016

ASN:
AS16276 OVH OVH SAS, FR

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Avira AntiVirus
TR/AD.TibiaStealer.Y.llpj
100.00%

Microsoft Security Essentials
Backdoor:MSIL/Noancooe.D
100.00%

McAfee
Artemis!D65F86F07AB6
100.00%

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
100.00%

Fortinet FortiGate
Malicious_Behavior.VEX.89
100.00%

AVG
Autoit
100.00%

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
100.00%

The domain tibiaiwindbot.com has been seen to resolve to the following 3 IP addresses.

205.ip-51-254-135.eu
August 3, 2016

164.ip-92-222-89.eu
May 20, 2016

225.ip-51-254-128.eu
April 14, 2016

File downloads found at URLs served by tibiaiwindbot.com.

7 / 68      (Malware)
http://tibiaiwindbot.com/windbot1092-2.7.8.exe  (d65f86f07ab6dee13cb39fadc6c4e7f6)

April 14, 2016

URL:
http://tibiaiwindbot.com/

Google Analytics:
UA-46758268

Title:
“WindBot - Home”

Description:
“WindBot is a high quality automation and enhancement software that functions alongside the Tibia client. It works by sending mouse clicks and keyboard strokes, displaying it's own visuals on top, facilitating player communication and is customiza...”

Web server:
Apache/2.4.16 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4