sandrasoft.com

Ivan Zaycev

Domain Information

The domain sandrasoft.com registered by Ivan Zaycev was initially registered in June of 2014 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Tuesday, June 24, 2014

Expires date:
Wednesday, June 24, 2015

Updated date:
Wednesday, October 15, 2014

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.InformationTechnologySystems.R, PUP.Installer.InformationTechnologySystems.Y, PUP.installCore.InformationTechnologySystems.Installer (M), PUP.installCore.Informat.Installer (M), PUP.installCore (M)
96.55%

Malwarebytes
PUP.Optional.Downloader, Trojan.Downloader
44.83%

Avira AntiVirus
ADWARE/InstallCore.Gen9, Adware/InstallCore.QH.3
44.83%

Dr.Web
Trojan.Packed.28409
44.83%

AVG
Generic
44.83%

VIPRE Antivirus
Threat.4150696
44.83%

ESET NOD32
Win32/InstallCore.PX potentially unwanted application
41.38%

K7 AntiVirus
Trojan
41.38%

SUPERAntiSpyware
PUP.InstallCore/Variant
41.38%

F-Prot
W32/InstallCore.AC.gen
41.38%

McAfee
Trojan.Artemis!460ECEB35134
41.38%

Clam AntiVirus
Win.Trojan.Installcore-231
34.48%

NANO AntiVirus
Riskware.Win32.InstallCore.dfgmcg, Riskware.Win32.InstallCore.dfgmnf
31.03%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
31.03%

Sophos
Install Core Click run software, PUA 'Install Core Click run software'
31.03%

The domain sandrasoft.com has been seen to resolve to the following 2 IP addresses.

ip-50-63-202-47.ip.secureserver.net
December 28, 2014

August 23, 2014

File downloads found at URLs served by sandrasoft.com.

The following 4 files have been seen to comunicate with sandrasoft.com in live environments.

URL:
http://sandrasoft.com/

Title:
“sandrasoft.com”

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)