rp.unesp.br

Carlos J. R. Coletti

Domain Information

Currently this domain has been known to host various forms of malware. The hosted servers are located in Sao Paulo, Sao Paulo within Brazil which resides on the Latin American and Caribbean IP address Regional Registry network.
Server location:
Sao Paulo, Brazil (BR)

ASN:
AS53166 UNIVERSIDADE ESTADUAL PAULISTA,BR

Root domain:

Scanner detections:
Malware distribution  (67% detected)

Scan engine
Details
Detections

avast!
Win32:Malware-gen
80.00%

Avira AntiVirus
TR/Downloader.A.26228, TR/Dldr.Agent.75776.23, TR/Downloader.A.27337, TR/Downloader.A.25458
80.00%

MicroWorld eScan
Gen:Variant.Kazy.713047, Trojan.GenericKD.2694028, Trojan.GenericKD.2629645
60.00%

ESET NOD32
MSIL/TrojanDownloader.Banload.EN
60.00%

Kaspersky
UDS:DangerousObject.Multi.Generic
60.00%

Bitdefender
Gen:Variant.Kazy.713047, Trojan.GenericKD.2694028, Trojan.GenericKD.2629645
60.00%

Lavasoft Ad-Aware
Gen:Variant.Kazy.713047, Trojan.GenericKD.2694028, Trojan.GenericKD.2629645
60.00%

Emsisoft Anti-Malware
Gen:Variant.Kazy.713047, Trojan.GenericKD.2694028, Trojan.GenericKD.2629645
60.00%

F-Secure
Gen:Variant.Kazy.713047, Trojan.GenericKD.2694028, Trojan.GenericKD.2629645
60.00%

VIPRE Antivirus
Trojan.Win32.Generic, Win32.Malware!Drop
60.00%

Arcabit
Trojan.Kazy.DAE157, Trojan.Generic.D291B8C, Trojan.Generic.D28200D
60.00%

G Data
Gen:Variant.Kazy.713047, Trojan.GenericKD.2694028, Trojan.GenericKD.2629645
60.00%

IKARUS anti.virus
Trojan.MSIL.Crypt, Trojan-Downloader
60.00%

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
60.00%

Sophos
Mal/Generic-S
60.00%

The domain rp.unesp.br has been seen to resolve to the following IP address.

yoda.unesp.br
February 10, 2016

File downloads found at URLs served by rp.unesp.br.

0 / 68
http://rp.unesp.br/.../chrome_update.exe  (f225bab1d0828455fdafdfe6dc172419)

23 / 68    (Malware)
http://rp.unesp.br/.../chrome_update.exe  (dc695de23c2a133a7a651498052822fa)

14 / 68    (Malware)
http://rp.unesp.br/.../chrome_update.exe  (1c190ca563bf212bbe04c523e4c28b72)

26 / 68    (Malware)
http://rp.unesp.br/.../chrome_update.exe  (7369f8db857aec26568bba6a6f060878)

0 / 68
http://rp.unesp.br/.../flash_install.exe  (19ca22985c3164201abfb1b113ff8ac4)

7 / 68      (Malware)
http://rp.unesp.br/.../chrome_update.exe  (1975327ed8fb540170c82fdd94a0d024)

URL:
http://rp.unesp.br/

Google Analytics:
UA-7191221

Title:
“UNESP: Reitoria - Portal da Universidade”

Web server:
Apache (PHP/5.3.3-7+squeeze19)

Facebook:
Shares:  1

Statistics are for the previous month.