www.tibiamulticlient.org

Michal Machowski

Domain Information

Currently this domain has been known to host various forms of malware. The hosted servers are located in Roubaix, Nord-Pas-De-Calais within France which resides on the RIPE Network Coordination Centre network.
Registrar:
NetArt Sp z o.o

Server location:
Nord-Pas-De-Calais, France (FR)

ASN:
AS16276 OVH OVH SAS,FR

Scanner detections:
Malware distribution  (67% detected)

Scan engine
Details
Detections

F-Prot
W32/AutoIt.CR.gen, W32/Virut.AL!Generic
66.67%

Dr.Web
Trojan.Packed.40821, Win32.Virut.56
66.67%

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra, Threat.4737366
66.67%

Trend Micro House Call
HKTL_GAMEHACK
33.33%

Trend Micro
HKTL_GAMEHACK
33.33%

Bkav FE
W32.HfsAtITSTIL
33.33%

ESET NOD32
Win32/Injector.Autoit.BZN
33.33%

Clam AntiVirus
Win.Trojan.Agent-57285
33.33%

Avira AntiVirus
DR/Autoit.A.15068
33.33%

Fortinet FortiGate
W32/Autoit.NLQ!tr
33.33%

Microsoft Security Essentials
Threat.Undefined
33.33%

avast!
Win32:Virtu-A
33.33%

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
33.33%

ESET NOD32
Win32/Virut.NBP virus
33.33%

F-Secure
Win32.Virtob.Gen.12
33.33%

The domain www.tibiamulticlient.org has been seen to resolve to the following IP address.

ks390189.kimsufi.com
May 15, 2016

File downloads found at URLs served by www.tibiamulticlient.org.

10 / 68    (Malware)
http://www.tibiamulticlient.org/neomc.exe  (88f66bc824fed3d409aa6b97b74ada3c)

8 / 68      (Malware)

2 / 68
http://www.tibiamulticlient.org/.../NeoMC.exe  (77120b7c8fe0983b6e84b9a19649b39a)

2 / 68
http://www.tibiamulticlient.org/neomc.exe  (77120b7c8fe0983b6e84b9a19649b39a)

URL:
http://www.tibiamulticlient.org/

Title:
“Tibia MC - NeoMC for all Tibia versions”

Web server:
Apache/2.2.16 (Debian)