www.freesoftwaren.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.freesoftwaren.com is registered by proxy through GODADDY.COM, LLC and was originally registered in September of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Hurth, Nordrhein-Westfalen within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Nordrhein-Westfalen, Germany (DE)

Create date:
Thursday, September 5, 2013

Expires date:
Monday, September 5, 2016

Updated date:
Thursday, September 10, 2015

ASN:
AS8972 PLUSSERVER-AS intergenia AG,DE

Root domain:

Scanner detections:
Detections  (90% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Outbrowse.ClickYes.Bundler (M), PUP.Adknowledge.Fileangels.Bundler (M), PUP.Adknowledge.SafeDown.Bundler (M), PUP.Outbrowse.Bundler (M), PUP.Outbrowse.SalyutemPlyus.Bundler (M), PUP.Outbrowse.Salyutem.Bundler (M), PUP.Outbrowse.OtopiaSO.Bundler (M), PUP.Adknowledge.Fileange.Bundler (M), PUP.Adknowledge.Fileprot.Installer (M), PUP.Adknowledge.Seekinst.Bundler (M), PUP.Outbrowse (M), PUP.Adknowledge (M)
97.78%

VIPRE Antivirus
Threat.4778314, Threat.4784459, OutBrowse
13.33%

Kaspersky
not-a-virus:AdWare.Win32.iBryte, Trojan.Win32.Badur, not-a-virus:AdWare.Win32.OutBrowse, not-a-virus:Downloader.NSIS.OutBrowse
13.33%

avast!
Win32:IBryte-HN [PUP], Win32:Adware-gen [Adw], Win32:IBryte-FS [PUP], Win32:OutBrowse-G [PUP], NSIS:OutBrowse-I [PUP]
13.33%

ESET NOD32
Win32/AdWare.iBryte.BK application, Win32/Adware.iBryte.BO application, Win32/OutBrowse.AY potentially unwanted application, Win32/OutBrowse.AU potentially unwanted application
13.33%

Dr.Web
Trojan.iBryte.521, Adware.iBryte.500, Adware.iBryte.493, Adware.Downware.1770, Detection.Undefined
13.33%

McAfee
Program.IBryte-FRT, Program.IBryte-FRK, Program.Adware-OutBrowse.b, Artemis!625AB4A96500
13.33%

Avira AntiVirus
ADWARE/iBryte.Gen4, Adware/iBryte.bxou, APPL/Downloader.Gen
11.11%

G Data
Win32.Adware.IBryte, Gen:Variant.Adware.158870, Application.Bundler.Outbrowse
11.11%

Fortinet FortiGate
W32/Zbot.AAN!tr, Riskware/NSIS_OutBrowse
11.11%

AVG
Adware AdPlugin.BOV, Downloader
11.11%

Malwarebytes
PUP.Optional.OptimunInstaller, PUP.Optional.OutBrowse
11.11%

Comodo Security
Application.Win32.AgentCV.HWYE, Application.Win32.OutBrowse.~A
11.11%

F-Prot
W32/A-34fffba4, W32/A-512ed8f8, W32/Outbrowse.A
11.11%

K7 AntiVirus
Unwanted-Program , Trojan
11.11%

The domain www.freesoftwaren.com has been seen to resolve to the following 5 IP addresses.

April 10, 2016

November 23, 2015

ip-50-63-202-56.ip.secureserver.net
September 21, 2015

static-ip-85-25-110-152.inaddr.ip-pool.com
October 9, 2014

charlie208.startdedicated.com
August 23, 2014

File downloads found at URLs served by www.freesoftwaren.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

2 / 68      (PUP)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

 
Latest 30 of 77 download URLs

The following 56 files have been seen to comunicate with www.freesoftwaren.com in live environments.

 
Latest 20 of 57 files

URL:
http://www.freesoftwaren.com/

Title:
“freesoftwaren.com”

Web server:
Apache