mc.ru-minecraft.org

Registrant of ru-minecraft.org

Domain Information

Currently this domain has been known to host various forms of malware. The hosted servers are located in Nuremberg, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
Instra Corporation Pty Ltd. (R1729-LROR)

Server location:
Bayern, Germany (DE)

ASN:
AS24940 HETZNER-AS Hetzner Online AG,DE

Root domain:

Scanner detections:
Malware distribution  (60% detected)

Scan engine
Details
Detections

Trend Micro House Call
TROJ_GEN.F47V0501, Suspicious_GEN.F47V0706, TROJ_GEN.F47V0510
60.00%

G Data
Win32.Application.RuMinecraft, Win32.Trojan.Agent.KR680X
40.00%

ESET NOD32
BAT/HostsChanger
40.00%

McAfee
Artemis!EE6F6633ECEC, Artemis!0102C5E211DF
40.00%

avast!
Win32:Malware-gen
40.00%

Sophos
Generic PUA DD, Generic PUA GI
40.00%

Avira AntiVirus
W32/Mabezat
20.00%

Reason Heuristics
nbsp;
20.00%

Comodo Security
UnclassifiedMalware
20.00%

Baidu Antivirus
Trojan.BAT.Qhost
20.00%

AVG
MultiDropper_c
20.00%

IKARUS anti.virus
Trojan.Win32.Qhost
20.00%

The domain mc.ru-minecraft.org has been seen to resolve to the following 2 IP addresses.

static.11.120.9.5.clients.your-server.de
May 28, 2014

hosted-by.spheral.ru
March 20, 2014

File downloads found at URLs served by mc.ru-minecraft.org.

8 / 68      (Malware)
http://mc.ru-minecraft.org/.../Minecraft-1.7.9-v0.7.5.exe  (ee6f6633ecec3a42832f5e159f8045ab)

1 / 68
http://mc.ru-minecraft.org/.../Minecraft-1.6.2-v0.7.5.exe  (175802f99e85eff0f01b6c077bce647b)

7 / 68      (Malware)
http://mc.ru-minecraft.org/.../Minecraft-1.6.2-v0.7.5.exe  (0102c5e211df58e52cfd567576d82abc)

1 / 68
http://mc.ru-minecraft.org/.../Minecraft-1.7.2-v0.7.5.exe  (9d87277369248ef2c23bd644427e7b74)

2 / 68      (Malware)
http://mc.ru-minecraft.org/.../Minecraft.exe  (3c166bae84553d4cb27af8abdc61712d)

The following 9 files have been seen to comunicate with mc.ru-minecraft.org in live environments.

URL:
http://mc.ru-minecraft.org/

Web server:
nginx/1.2.1