bikotl76.bget.ru

Private Person  (Proxy Registrant)

Domain Information

The domain bikotl76.bget.ru is registered by proxy through R01-RU and was originally registered in April of 2008. Currently this domain has been known to host various forms of malware. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
R01-RU

Server location:
Moscow City, Russia (RU)

Create date:
Wednesday, April 9, 2008

Expires date:
Sunday, April 9, 2017

ASN:
AS198610 BEGET-AS Beget Ltd, RU

Root domain:

Google Safe Browsing:
malware,unwanted

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/Packed.Obsidium.AG (variant), MSIL/GameHack.F potentially unsafe (variant)
66.67%

avast!
Win32:Malware-gen, MSIL:GameHack-C [PUP]
66.67%

Sophos
Mal/EncPk-UL, Mal/MSIL-AZ
66.67%

AegisLab AV Signature
Backdoor.W32.Singu.lhbk, HackTool.W32.GameHuck.m00n
66.67%

G Data
Win32.Trojan.Agent.PII4PQ, Gen:Variant.MSILPerseus.26345
66.67%

IKARUS anti.virus
Trojan.Win32.Obsidium, Trojan-Downloader
66.67%

Fortinet FortiGate
PossibleThreat, Malware_Generic.P0
66.67%

Qihoo 360 Security
HEUR/QVM18.1.Malware.Gen, HEUR/QVM03.0.Malware.Gen
66.67%

McAfee
Artemis!0E425C54AF1B, Trojan.Artemis!810F24AC80DB
66.67%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696
66.67%

Bkav FE
HW32.Packed
33.33%

Comodo Security
TrojWare.Win32.TrojanDropper.Small.DA
33.33%

AVG
Atros3
33.33%

MicroWorld eScan
Gen:Variant.MSILPerseus.26345
33.33%

Bitdefender
Gen:Variant.MSILPerseus.26345
33.33%

The domain bikotl76.bget.ru has been seen to resolve to the following IP address.

m2.klipper.beget.com
May 24, 2016

File downloads found at URLs served by bikotl76.bget.ru.

18 / 68    (PUP)
http://bikotl76.bget.ru/updater/soft/.../cheat6.exe  (0e425c54af1ba072af850c6b16c4912d)

11 / 68    (Malware)
http://bikotl76.bget.ru/updater/soft/.../rungame.exe  (e9742043f1d9503aeab350b33759fe63)

5 / 68      (Malware)
http://bikotl76.bget.ru/updater/soft/.../cheat7.exe  (c3eee8acb9f946bc478d34e6af5df97c)

URL:
http://bikotl76.bget.ru/

Title:
“Сайт блокирован хостинг-провайдером! Хостинг-провайдер BeGet.ru”

Web server:
nginx-reuseport/1.10.0