software.softwareserver04.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain software.softwareserver04.com is registered by proxy through GODADDY.COM, LLC and was originally registered in April of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Chicago, Illinois within the United States which resides on the Hosting Services, Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Illinois, United States (US)

Create date:
Thursday, April 23, 2015

Expires date:
Saturday, April 23, 2016

Updated date:
Thursday, April 23, 2015

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Scanner detections:
Detections  (56% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.DriverSoft.DriverIn.Installer.Meta (L), PUP.Win.Reputation, PUP.MediaDownloader.Installer.Meta (M), PUP.MediaDownder.IC
57.14%

Malwarebytes
PUP.Optional.Media, PUP.Optional.BundleInstaller
42.86%

K7 AntiVirus
Trojan , Riskware
42.86%

Trend Micro House Call
Suspicious_GEN.F47V0507, Suspicious_GEN.F47V0423
42.86%

McAfee
Artemis!ED8513690F80, Virus.W32/Sality.gen.z
28.57%

ESET NOD32
Win32/Sality.NBA virus, Detection.Undefined
28.57%

Dr.Web
Win32.Sector.30, Adware.Downware.12544
28.57%

VIPRE Antivirus
Threat.4721115
14.29%

F-Prot
W32/Sality.gen2
14.29%

F-Secure
Win32.Sality.3
14.29%

Microsoft Security Essentials
Threat.Undefined
14.29%

Emsisoft Anti-Malware
Win32.Sality
14.29%

Norman
Win32.Sality.3
14.29%

avast!
Win32:SaliCode
14.29%

Kaspersky
Virus.Win32.Sality
14.29%

The domain software.softwareserver04.com has been seen to resolve to the following 2 IP addresses.

July 14, 2016

no-rdns.ord02.hostingservicesinc.net
October 13, 2015

File downloads found at URLs served by software.softwareserver04.com.

0 / 68
http://software.softwareserver04.com/.../setup.exe  (6c50f565abe9ea5afe4a2139ed70f949)

1 / 68      (PUP)

1 / 68      (inconclusive)
http://software.softwareserver04.com/.../setup.exe  (5c9e56c34d8bfd17c84b9fc8316227d8)

2 / 68      (PUP)

14 / 68    (Infected)

7 / 68      (PUP)
http://software.softwareserver04.com/MediaDownloader.exe  (b9733b1022724e6e2d39647436668b3d)

1 / 68      (PUP)

4 / 68      (inconclusive)
http://software.softwareserver04.com/.../setup.exe  (ed8513690f8092d9aa0ac4eea6e53449)

The following 3 files have been seen to comunicate with software.softwareserver04.com in live environments.

URL:
http://software.softwareserver04.com/

Web server:
Apache/2.2.15 (CentOS)