villabuena.sslblindado.com

Universo Online SA

Domain Information

The domain villabuena.sslblindado.com registered by Universo Online SA was initially registered in November of 2007 through GODADDY.COM, LLC. Currently this domain has been known to host various forms of malware. The hosted servers are located in Sao Paulo, Sao Paulo within Brazil which resides on the Latin American and Caribbean IP address Regional Registry network.
Registrar:
GODADDY.COM, LLC

Server location:
Sao Paulo, Brazil (BR)

Create date:
Friday, November 16, 2007

Expires date:
Wednesday, November 16, 2016

Updated date:
Saturday, July 25, 2015

ASN:
AS7162 Universo Online S.A.,BR

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

avast!
Win32:Malware-gen
100.00%

ESET NOD32
MSIL/TrojanDownloader.Agent.BMO trojan
100.00%

Emsisoft Anti-Malware
Gen:Variant.Kazy.780508
100.00%

Microsoft Security Essentials
Threat.Undefined
100.00%

F-Secure
Variant.Kazy.780508
100.00%

The domain villabuena.sslblindado.com has been seen to resolve to the following IP address.

May 20, 2016

File downloads found at URLs served by villabuena.sslblindado.com.

5 / 68      (Malware)

URL:
http://villabuena.sslblindado.com/

Title:
“Villa Buena Vista”

SSL certificate subject:
CN=*.sslblindado.com, O=Universo Online SA, L=Sao Paulo, S=Sao Paulo, C=BR

SSL certificate issuer:
CN=GeoTrust SHA256 SSL CA, O=GeoTrust Inc., C=US

Web server:
Microsoft-IIS/8.0 (ASP.NET)