ai.direct-software.com

PERFECT PRIVACY, LLC  (Proxy Registrant)

Domain Information

The domain ai.direct-software.com is registered by proxy through Network Solutions, LLC and was originally registered in September of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in New York City, New York within the United States which resides on the Digital Ocean, Inc. network.
Registrar:
Network Solutions, LLC

Server location:
New York, United States (US)

Create date:
Friday, September 5, 2014

Expires date:
Monday, September 5, 2016

Updated date:
Tuesday, July 7, 2015

ASN:
AS393406 DIGITALOCEAN-ASN-NY3 - Digital Ocean, Inc.,US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Bundler.Air Software, PUP.Air Software.DownloadAssistant.Bundler (M), PUP.Vittalia.SoftwareAssistant.Installer (M), PUP.Vittalia.Software.Installer (M)
100.00%

avast!
Win32:Adware-CKC [PUP]
75.00%

VIPRE Antivirus
Threat.4782985, AirInstaller
50.00%

Dr.Web
Trojan.Vittalia.30
50.00%

Bkav FE
W32.HfsAdware
50.00%

Avira AntiVirus
TR/Crypt.XPACK.Gen
50.00%

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
50.00%

ESET NOD32
Win32/DownloadAssistant.A potentially unwanted application
25.00%

NANO AntiVirus
Trojan.Win32.DownloadHelper.dpgylc
25.00%

AhnLab V3 Security
PUP/Win32.Bundler
25.00%

ESET NOD32
Win32/DownloadAssistant.A potentially unwanted (variant)
25.00%

The domain ai.direct-software.com has been seen to resolve to the following 2 IP addresses.

fd-03-do-e-ny-3.gtdlrfwd.com
March 3, 2016

useast.gtdlrfwd.com
April 8, 2015

File downloads found at URLs served by ai.direct-software.com.

The following 14 files have been seen to comunicate with ai.direct-software.com in live environments.

URL:
http://ai.direct-software.com/

Title:
“Welcome to nginx!”

Web server:
nginx/1.4.6 (Ubuntu)