i.getfree-soft.net

PERFECT PRIVACY, LLC  (Proxy Registrant)

Domain Information

The domain i.getfree-soft.net is registered by proxy through Network Solutions, LLC and was originally registered in January of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
Network Solutions, LLC

Server location:
Virginia, United States (US)

Create date:
Monday, January 6, 2014

Expires date:
Tuesday, January 6, 2015

Updated date:
Wednesday, January 22, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Google Safe Browsing:
phishing

Scanner detections:
Detections  (86% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Win.Reputation, PUP.UsefulSoftware.L, PUP.Nextup.BB, PUP.Nextup.V, PUP.Nextup.S, PUP.WecanSoftware.BB, PUP.Adknowledge.Nextup.Bundler (M), PUP.Verti.UsefulSo.Bundler (M)
92.86%

VIPRE Antivirus
Threat.4786530, Rocketfuel Installer, Trojan.Win32.Generic
71.43%

Sophos
Verti, NextUp, Generic PUA GD
71.43%

McAfee
Artemis!C96BD5645D12, Program.Artemis!20BED7603DED, Artemis!A099AF31B982, Artemis!71F42C6F6AF0, Artemis!6B65D132CADE
64.29%

Trend Micro House Call
Suspicious_GEN.F47V0708, Suspicious_GEN.F47V1205, Suspicious_GEN.F47V1219, TROJ_GEN.R047C0OLK14
64.29%

G Data
Application.Bundler, Win32.Application.Nextup, Trojan.Generic.12186129
57.14%

Malwarebytes
PUP.Optional.NextUp, PUP.Optional.WeCan.A
57.14%

K7 AntiVirus
Trojan
57.14%

ESET NOD32
Win32/Verti (variant)
57.14%

IKARUS anti.virus
PUA.Nextup, PUA.Verti
57.14%

Vba32 AntiVirus
AdWare.Agent, AdWare.Verti
50.00%

AVG
Usefus, Wecan, Generic
28.57%

herdProtect (fuzzy)
a variant of b7759118ab4a1ac5b17c2c37451b4eff78b48f30, a variant of c69099e5c5740cde0d4b65d922e49e2b264ac7f7, a variant of 06722041927d2c35cebe75566c3218a517980ad9
28.57%

Dr.Web
Adware.Downware.5905, Adware.Downware.9414
28.57%

avast!
Win32:PUP-gen [PUP]
21.43%

The domain i.getfree-soft.net has been seen to resolve to the following 60 IP addresses.

server-54-230-141-220.sfo5.r.cloudfront.net
August 10, 2016

server-54-230-141-219.sfo5.r.cloudfront.net
August 10, 2016

server-54-230-141-73.sfo5.r.cloudfront.net
August 10, 2016

server-54-230-141-46.sfo5.r.cloudfront.net
August 10, 2016

server-54-230-141-20.sfo5.r.cloudfront.net
August 10, 2016

server-54-230-141-249.sfo5.r.cloudfront.net
August 10, 2016

server-54-230-141-246.sfo5.r.cloudfront.net
August 10, 2016

server-54-230-141-234.sfo5.r.cloudfront.net
August 10, 2016

server-52-85-131-131.iad53.r.cloudfront.net
May 18, 2016

server-52-85-131-124.iad53.r.cloudfront.net
May 18, 2016

server-52-85-131-111.iad53.r.cloudfront.net
May 18, 2016

server-52-85-131-45.iad53.r.cloudfront.net
May 18, 2016

server-52-85-131-22.iad53.r.cloudfront.net
May 18, 2016

server-52-85-131-180.iad53.r.cloudfront.net
May 18, 2016

server-52-85-131-173.iad53.r.cloudfront.net
May 18, 2016

server-52-85-131-144.iad53.r.cloudfront.net
May 18, 2016

server-54-230-36-204.jfk1.r.cloudfront.net
May 4, 2015

server-54-230-36-115.jfk1.r.cloudfront.net
May 4, 2015

server-54-230-38-177.jfk1.r.cloudfront.net
May 4, 2015

server-54-230-39-194.jfk1.r.cloudfront.net
May 4, 2015

server-54-230-39-52.jfk1.r.cloudfront.net
May 4, 2015

server-54-192-36-76.jfk1.r.cloudfront.net
May 4, 2015

server-54-230-36-56.jfk1.r.cloudfront.net
May 4, 2015

server-54-230-38-222.jfk1.r.cloudfront.net
May 4, 2015

server-54-192-54-198.jfk6.r.cloudfront.net
May 3, 2015

server-54-230-53-82.jfk6.r.cloudfront.net
May 3, 2015

server-54-192-54-173.jfk6.r.cloudfront.net
May 3, 2015

server-54-230-52-91.jfk6.r.cloudfront.net
May 3, 2015

server-54-192-55-161.jfk6.r.cloudfront.net
May 3, 2015

server-54-192-54-195.jfk6.r.cloudfront.net
May 3, 2015

 
Showing 30 of 60 IP Addresses

File downloads found at URLs served by i.getfree-soft.net.

1 / 68      (Adware)

2 / 68      (false positives)

1 / 68      (Adware)

1 / 68      (false positive)

2 / 68      (false positives)

10 / 68    (Adware)

11 / 68    (Adware)

30 / 68    (Adware)

10 / 68    (Adware)
http://i.getfree-soft.net/stub/.../Strongvault.exe  (45de526cae8cdd58dd3f3bdcef4a59ca)

13 / 68    (Adware)

14 / 68    (Adware)
http://i.getfree-soft.net/stub/.../PopcornTVInstaller.exe  (bf8ede79d3a6946660143ff3a41d6636)

14 / 68    (Adware)

12 / 68    (Adware)
http://i.getfree-soft.net/stub/.../PopcornTVInstaller.exe  (4ec24a53295d1ea73ea3285b3547395c)

14 / 68    (Adware)

11 / 68    (Adware)

The following 457 files have been seen to comunicate with i.getfree-soft.net in live environments.

 
Latest 20 of 613 files

URL:
http://i.getfree-soft.net/

Network:
Amazon Cloudfront

Web server:
AmazonS3