www.gameplaybr.net

Danilo Martins

Domain Information

The domain www.gameplaybr.net registered by Danilo Martins was initially registered in September of 2014 through DIGIRATI INFORMATICA SERVICOS E TELECOMUNICACOES LTDA DBA HOSTNET.COM. Currently this domain has been known to host various forms of malware. The hosted servers are located in Sao Paulo, Sao Paulo within Brazil which resides on the Latin American and Caribbean IP address Regional Registry network.
Registrar:
DIGIRATI INFORMATICA SERVICOS E TELECOMUNICACOES LTDA DBA HOSTNET.COM

Server location:
Sao Paulo, Brazil (BR)

Create date:
Friday, September 19, 2014

Expires date:
Monday, September 19, 2016

Updated date:
Monday, January 25, 2016

ASN:
AS7162 Universo Online S.A.,BR

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Kaspersky
Trojan.Win32.Banamed, Trojan-Banker.Win32.Banbra, Trojan-Dropper.Win32.Agent
100.00%

Panda Antivirus
Trj/Chgt.I, W32/Cosmu.gen, Trj/CI.A, Trj/Chgt.H
83.33%

Baidu Antivirus
Trojan.Win32.Banload, Trojan.Win32.Banamed, Trojan.Win32.Banker, Trojan.Win32.Dropper
83.33%

VIPRE Antivirus
Threat.4726519, Trojan.Win32.Generic
66.67%

Sophos
Virus 'W32/Patched-I', Mal/Generic-S
66.67%

Bkav FE
HW32.Paked
50.00%

IKARUS anti.virus
Trojan.Win32.Banamed, Trojan-Downloader.Win32.Banload, Trojan-Dropper.Win32.Agent
50.00%

Reason Heuristics
Threat.Win.Reputation.IMP
50.00%

Microsoft Security Essentials
Threat.Undefined
50.00%

K7 AntiVirus
Virus
50.00%

Norman
Krap.XK
50.00%

McAfee
Artemis!27DE1054631E, Artemis!8B59C661631D, Artemis!7C21B7ED6425
50.00%

MicroWorld eScan
Trojan.GenericKD.1881187, Trojan.GenericKD.1907660, Gen:Variant.Symmi.46836
50.00%

Bitdefender
Trojan.GenericKD.1881187, Trojan.GenericKD.1907660, Gen:Variant.Symmi.46836
50.00%

Lavasoft Ad-Aware
Trojan.GenericKD.1881187, Trojan.GenericKD.1907660, Gen:Variant.Symmi.46836
50.00%

The domain www.gameplaybr.net has been seen to resolve to the following IP address.

200-98-151-45.clouduol.com.br
October 9, 2014

File downloads found at URLs served by www.gameplaybr.net.

9 / 68      (Malware)
http://www.gameplaybr.net/.../?flashplayer  (install_flashplayer15x32_mssa_aaa_aih.exe)

12 / 68    (Malware)
http://www.gameplaybr.net/.../?flashplayer  (atualizar_flash_player.exe)

12 / 68    (Malware)
http://www.gameplaybr.net/.../?flashplayer  (install_flashplayer15x32_mssa_aaa_aih.exe)

18 / 68    (Malware)
http://www.gameplaybr.net/.../?flashplayer  (install_flashplayer15x32_mssa_aaa_aih.exe)

11 / 68    (Malware)
http://www.gameplaybr.net/.../?flashplayer  (install_flashplayer15x32_mssa_aaa_aih.exe)

13 / 68    (Malware)
http://www.gameplaybr.net/.../?flashplayer  (install_flashplayer15x32_mssa_aaa_aih.exe)