gsm.unesp.br

UNIVERSIDADE ESTADUAL PAULISTA (14873)

Domain Information

Currently this domain has been known to host various forms of malware. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Server location:
Northern Ireland, United Kingdom (GB)

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

avast!
Win32:Dropper-gen [Drp]
100.00%

Sophos
Troj/MSIL-DAR
100.00%

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
100.00%

MicroWorld eScan
Trojan.Generic.14610753
100.00%

nProtect
Trojan.Generic.14610753
100.00%

McAfee
RDN/Generic.tfr!eo
100.00%

K7 AntiVirus
Riskware
100.00%

Bitdefender
Trojan.Generic.14610753
100.00%

Arcabit
Trojan.Generic.DDEF141
100.00%

Trend Micro House Call
TROJ_BANLOAD.YWNIR
100.00%

Lavasoft Ad-Aware
Trojan.Generic.14610753
100.00%

F-Secure
Trojan.Generic.14610753
100.00%

VIPRE Antivirus
Trojan.Win32.Generic
100.00%

Trend Micro
TROJ_BANLOAD.YWNIR
100.00%

Emsisoft Anti-Malware
Trojan.Generic.14610753
100.00%

The domain gsm.unesp.br has been seen to resolve to the following IP address.

unallocated.barefruit.co.uk
June 18, 2015

File downloads found at URLs served by gsm.unesp.br.

21 / 68    (Malware)
http://gsm.unesp.br/Software/.../flash_install.exe  (90e4c75bd422a027622394e1c5626b42)

The following 230 files have been seen to comunicate with gsm.unesp.br in live environments.

 
Latest 20 of 230 files

URL:
http://gsm.unesp.br/

Web server:
nginx/1.0.15