download.solvusoft.com

Solvusoft Corporation

Domain Information

The domain download.solvusoft.com registered by Solvusoft Corporation was initially registered in May of 2011 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Registrar:
GODADDY.COM, LLC

Server location:
Oregon, United States (US)

Create date:
Tuesday, May 24, 2011

Expires date:
Tuesday, May 24, 2016

Updated date:
Thursday, April 16, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (89% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.WinThruster.SolvusoftCorporation.Installer.Meta (L), PUP.Solvusoft.Installer.Meta (L), PUP.Win.Reputation.SolvusoftCorporation, PUP.WinThruster.solvusoftCorporation.Installer.Meta (L), PUP.WinThruster.Solvusof.Installer.Meta (L), PUP.InstallerGenius.Installer (M), PUP (M), PUP.WinThruster.solvusof.Installer.Meta (L), PUP.WinThruster (L)
88.89%

ESET NOD32
Win32/Systweak.R potentially unwanted application, Win32/Solvusoft.B potentially unwanted application, Win32/Delf.NRJ worm
16.67%

Dr.Web
riskware program Program.Unwanted.1230, riskware program Program.Unwanted.1396, Trojan.Inject1.28681
16.67%

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant), Win32/AdvancedSystemProtector
11.11%

Emsisoft Anti-Malware
Gen:Variant.Kazy.1260, Worm.Generic.377772
11.11%

Kaspersky
not-a-virus:RiskTool.Win32.SystemTweaker, Virus.Win32.Renamer
11.11%

VIPRE Antivirus
Threat.4150696
5.56%

Microsoft Security Essentials
Threat.Undefined
5.56%

F-Prot
W32/Renamer.A.gen
5.56%

avast!
Win32:Agent-AODJ [Trj]
5.56%

F-Secure
Worm.Generic.377772
5.56%

Norman
Worm.Generic.377772
5.56%

The domain download.solvusoft.com has been seen to resolve to the following 5 IP addresses.

ec2-54-191-183-106.us-west-2.compute.amazonaws.com
April 13, 2016

ec2-54-191-183-14.us-west-2.compute.amazonaws.com
April 10, 2016

ec2-54-148-47-177.us-west-2.compute.amazonaws.com
May 4, 2015

September 3, 2014

August 4, 2013

File downloads found at URLs served by download.solvusoft.com.

4 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

4 / 68      (PUP)

4 / 68      (PUP)

1 / 68      (PUP)

9 / 68      (Malware)

0 / 68

2 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (inconclusive)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://download.solvusoft.com/downloads/.../DriverDoc_2014.exe  (hangkã¡rtya_illesztőprogram_frissítése_11-2013.exe)

1 / 68      (PUP)

1 / 68      (PUP)

2 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://download.solvusoft.com/downloads/.../DriverDoc_2013_a.exe  (hangkã¡rtya_illesztőprogram_frissítése_11-2013.exe)

1 / 68      (PUP)

2 / 68      (PUP)

The following 3 files have been seen to comunicate with download.solvusoft.com in live environments.

URL:
http://download.solvusoft.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
SSWS