updater.godworld.ru

Private Person  (Proxy Registrant)

Domain Information

The domain updater.godworld.ru is registered by proxy through REGRU-REG-RIPN and was originally registered in August of 2011. Currently this domain has been known to host various forms of malware. The hosted servers are located in Roubaix, Nord-Pas-De-Calais within France which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-REG-RIPN

Server location:
Nord-Pas-De-Calais, France (FR)

Create date:
Wednesday, August 10, 2011

Expires date:
Sunday, August 10, 2014

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

nProtect
Trojan/W32.Agent.1311232.K
100.00%

Norman
OnLineGames.OJQL
100.00%

Trend Micro House Call
TROJ_GEN.F47V1005
100.00%

Jiangmin
TrojanDownloader.Genome.aeky
100.00%

Kingsoft AntiVirus
Win32.Malware.Heur_Generic.A.(kcloud)
100.00%

The domain updater.godworld.ru has been seen to resolve to the following IP address.

167.ip-37-187-53.eu
December 27, 2013

File downloads found at URLs served by updater.godworld.ru.

5 / 68      (Malware)
http://updater.godworld.ru/godworld.exe  (054b7fed211095278f9d24832144f1f6)

URL:
http://updater.godworld.ru/

Title:
“Ertheia: GodWorld - Lineage 2 Goddess of Destruction: Ertheia”

Description:
“Lineage 2: Goddess of Destruction - Ertheia, сервер Lindvior, Epeisodion, God, хроники Ertheia, Артеас, la2, l2”

Web server:
nginx/1.2.1 (PHP/5.4.4-14+deb7u5)

Alexa:
Global rank:  5,245,167
Backlinks:  15

Statistics are for the previous month (Alexa statistics are for entire godworld.ru).