games.softango.com

Softango Technology LLC  (via a Proxy Registrant)

Domain Information

Softango is an adware distribution web site (from iBario) that uses the InstallBrain download manager to distribute potentially unwanted ad-supported software via download bundles in the site's directory of programs (PerformerSoft and open source products). The domain games.softango.com is registered by proxy through Moniker Online Services and was originally registered in May of 2011. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Washington, Virginia within the United States which resides on the SoftLayer Technologies Inc. network. The domain is associated with the publisher Softango Technology LLC who is located in Beaverton, Oregon in the United States.
Registrar:
Moniker Online Services

Server location:
Virginia, United States (US)

Create date:
Wednesday, May 4, 2011

Expires date:
Wednesday, May 4, 2016

Updated date:
Tuesday, December 22, 2015

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SoftangoTechnology.FF, PUP.SoftangoTechnology.j, PUP.SoftangoTechnology.e, PUP.Performersoft.WeCodeGood.Bundler (M)
100.00%

Dr.Web
Adware.Downware.2543, Trojan.DownLoader11.36243, Adware.Downware.3914
80.00%

AVG
MalSign.Generic, InstallBrain, Adware InstallBrain.AB
80.00%

ESET NOD32
Win32/InstallBrain.BW (variant), Win32/InstallBrain.CQ (variant)
60.00%

Kaspersky
not-a-virus:AdWare.Win32.BrainInst, not-a-virus:AdWare.Win32.InstallBrain
60.00%

MicroWorld eScan
Application.Bundler.InstallBrain.E, Gen:Variant.Jaik.2984
60.00%

Malwarebytes
PUP.Optional.Softango.A
60.00%

K7 AntiVirus
Unwanted-Program
60.00%

Bitdefender
Application.Bundler.InstallBrain.E, Gen:Variant.Jaik.2984
60.00%

F-Secure
Application.Bundler.InstallBrain, Gen:Variant.Jaik.2984
60.00%

Zillya! Antivirus
Adware.BrainInst.Win32.126, Trojan.Black.Win32.16744
60.00%

F-Prot
W32/A-3442f84d, W32/A-03a716bb
60.00%

Avira AntiVirus
ADWARE/InstallBrain.Gen, APPL/InstallBrain.Gen
60.00%

AhnLab V3 Security
PUP/Win32.InstallBrain
60.00%

G Data
Application.Bundler.InstallBrain, Gen:Variant.Jaik.2984
60.00%

The domain games.softango.com has been seen to resolve to the following 13 IP addresses.

50.23.135.221-static.reverse.softlayer.com
April 1, 2016

50.97.57.37-static.reverse.softlayer.com
April 1, 2016

50.23.135.216-static.reverse.softlayer.com
November 29, 2014

208.43.244.224-static.reverse.softlayer.com
April 13, 2014

184.173.139.224-static.reverse.softlayer.com
April 13, 2014

50.97.56.104-static.reverse.softlayer.com
April 13, 2014

50.97.40.168-static.reverse.softlayer.com
April 13, 2014

208.43.230.160-static.reverse.softlayer.com
April 13, 2014

108.168.162.216-static.reverse.softlayer.com
April 13, 2014

50.97.57.32-static.reverse.softlayer.com
April 13, 2014

208.43.249.112-static.reverse.softlayer.com
April 13, 2014

208.43.236.200-static.reverse.softlayer.com
April 13, 2014

208.43.224.240-static.reverse.softlayer.com
April 13, 2014

File downloads found at URLs served by games.softango.com.

1 / 68      (Adware)
http://games.softango.com/.../157782.html  (fastlanepinball_softangodownloader.exe)

24 / 68    (Adware)
http://games.softango.com/.../157830  (SoftangoDownloader_HiddenWorldOfArt2.exe)

17 / 68    (Adware)
http://games.softango.com/.../157722  (SoftangoDownloader_CrazyChickenKart2.exe)

17 / 68    (Adware)
http://games.softango.com/.../157990  (SoftangoDownloader_SnowyTheBearsAdventure.exe)

4 / 68      (Adware)
http://games.softango.com/.../157701.html  (SoftangoDownloader_ChainzGalaxy.exe)

The following 4 files have been seen to comunicate with games.softango.com in live environments.

URL:
http://games.softango.com/

Google Analytics:
UA-52518593

Title:
“Games - Softango”

Web server:
nginx (PHP/5.4.17)

Facebook:
Likes:  658
Shares:  59
Comments:  3

Statistics are for the previous month.