www.windowpar.com

kim jin mo

Domain Information

The domain www.windowpar.com registered by kim jin mo was initially registered in April of 2011 through KOREACENTER.COM CO., LTD. Currently this domain has been known to host various forms of malware. The hosted servers are located in Anyang, Kyonggi-Do within Korea which resides on the Asia Pacific Network Information Centre network.
Registrar:
KOREACENTER.COM CO., LTD

Server location:
Kyonggi-Do, Korea (KR)

Create date:
Monday, April 25, 2011

Expires date:
Tuesday, April 25, 2017

Updated date:
Monday, April 25, 2016

ASN:
AS45996 GNJ-AS-KR G&J, LTD.,KR

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

McAfee
Artemis!7CC2E7740922
100.00%

Malwarebytes
Trojan.Agent.SL
100.00%

Norman
Suspicious_Gen4.ELGAK
100.00%

Trend Micro House Call
TROJ_GEN.R0CBB01IU13
100.00%

Sophos
Mal/Generic-S
100.00%

Comodo Security
UnclassifiedMalware
100.00%

VIPRE Antivirus
Trojan.Win32.Generic
100.00%

Baidu Antivirus
Trojan.MSIL.Spy.Agent
100.00%

ViRobot
JS.A.Iframe.80384.E
100.00%

ESET NOD32
MSIL/Spy.Agent.IZ (variant)
100.00%

IKARUS anti.virus
Trojan-PWS.MSIL
100.00%

Fortinet FortiGate
MSIL/Agent.IZ!tr.spy
100.00%

AVG
PSW.MSIL
100.00%

Panda Antivirus
Suspicious file
100.00%

The domain www.windowpar.com has been seen to resolve to the following IP address.

June 25, 2016

File downloads found at URLs served by www.windowpar.com.

14 / 68    (Malware)
http://www.windowpar.com/SystemInfoLOG.exe  (7cc2e7740922326f9163ddfdc29a368b)

URL:
http://www.windowpar.com/

Title:
“Installed Software Information”

Description:
“Installed Software Information”

Web server:
Apache (PHP/5.3.3)