www.winbooks.com.br

Marcelo Felisbino Andrade

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Sao Paulo, Sao Paulo within Brazil which resides on the Latin American and Caribbean IP address Regional Registry network.
Server location:
Sao Paulo, Brazil (BR)

ASN:
AS7162 Universo Online S.A.,BR

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Kaspersky
not-a-virus:RemoteAdmin.Win32.Agent, not-a-virus:RemoteAdmin.Win32.WinVNC
100.00%

Bkav FE
W32.Clod820.Trojan, W32.Clod9e1.Trojan
100.00%

K7 AntiVirus
Unwanted-Program , Riskware
100.00%

VIPRE Antivirus
Trojan.Win32.Generic, RealVNC (not malicious)
100.00%

Baidu Antivirus
HackTool.Win32.RemoteAdmin, HackTool.Win32.WinVNC
100.00%

ESET NOD32
Win32/RemoteAdmin.Ammyy (variant)
50.00%

Rising Antivirus
PE:Malware.Ammyy!6.854
50.00%

Reason Heuristics
PUP.Ammyy.F
50.00%

NANO AntiVirus
Trojan.Win32.RemoteAdmin.cqwpdg
50.00%

avast!
Win32:PUP-gen [PUP]
50.00%

Agnitum Outpost
Riskware.RemoteAdmin
50.00%

nProtect
Trojan/W32.Agent.730960
50.00%

Avira AntiVirus
SPR/RemoteAdmin.AB
50.00%

Dr.Web
Program.RemoteAdmin.701
50.00%

Comodo Security
UnclassifiedMalware
50.00%

The domain www.winbooks.com.br has been seen to resolve to the following IP address.

whw0033.whservidor.com
August 16, 2014

File downloads found at URLs served by www.winbooks.com.br.

7 / 68      (PUP)
http://www.winbooks.com.br/.../UltraVNC_Clic.exe  (bafb14f4eaf62226438f637e204b5b86)

16 / 68    (Adware)
http://www.winbooks.com.br/.../AA_v3.exe  (f9cde592fcd907fb00807124df17c2f1)

URL:
http://www.winbooks.com.br/

Title:
“Untitled Document”

Web server:
Microsoft-IIS/7.0 (ASP.NET)