www.performersoft.com

Performersoft LLC

Domain Information

The domain www.performersoft.com registered by iBario LTD was initially registered in April of 2010 through Moniker Online Services. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Washington, Virginia within the United States which resides on the SoftLayer Technologies Inc. network. The domain is associated with the publisher Performersoft LLC who is located in Beaverton, Oregon in the United States.
Registrar:
Moniker Online Services

Server location:
Virginia, United States (US)

Create date:
Wednesday, April 14, 2010

Expires date:
Friday, April 14, 2017

Updated date:
Sunday, April 3, 2016

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Performersoft.AA, PUP.Installer.Performersoft.Q, PUP.Installer.Performersoft.U, PUP.Installer.Performersoft.Y, PUP.Installer.Performersoft.R, PUP.Performersoft.InstallBrain.Installer (M), PUP.Performersoft.InstallB.Installer (M)
100.00%

Avira AntiVirus
APPL/InstallBrain.Gen5, TR/Strictor.13903.1, ADWARE/Adware.Gen7, APPL/InstallIQ.Gen5
80.00%

Comodo Security
ApplicUnwnt.Win32.AdWare.IBrain.B, Application.Win32.InstallIQ.NTZK
70.00%

VIPRE Antivirus
InstallBrain, InstallIQ Installer, Threat.4759033
70.00%

Dr.Web
Adware.Downware.371, Adware.W3i.3, Adware.Downware.281
60.00%

ESET NOD32
Win32/InstallBrain (variant), Win32/InstallIQ (variant)
60.00%

Fortinet FortiGate
Adware/Fam.NB, Riskware/InstallBrain, Adware/InstallBrain, Adware/Sofagn, Adware/InstallIQ, W32/Obfuscated.NEV!tr
60.00%

F-Prot
W32/IBrain.B.gen, W32/IBrain.B2.gen, W32/IBrain.A.gen
50.00%

Sophos
InstallBrain
50.00%

Microsoft Security Essentials
TrojanDownloader:Win32/Brantall.A, TrojanDownloader:Win32/Brantall.E, Threat.Undefined
50.00%

Panda Antivirus
PUP/Ibups, Adware/Ibups
50.00%

MicroWorld eScan
ADWARE/InstallBrain.Gen, Application.Bundler.InstallBrain.A
40.00%

Malwarebytes
Adware.InstallBrain, PUP.Optional.InstallIQ.A
40.00%

Trend Micro House Call
TROJ_GEN.R0CBC0OI813, TROJ_GEN.R0CBOH0K513, TROJ_SPNR.0CGF13, HV_INSTALLBRAIN_CA225D33.TOMC
40.00%

IKARUS anti.virus
Trojan-Downloader.Win32.Brantall, Luhe.InstallBrain
40.00%

The domain www.performersoft.com has been seen to resolve to the following 12 IP addresses.

50.97.57.37-static.reverse.softlayer.com
February 3, 2016

50.23.135.221-static.reverse.softlayer.com
February 3, 2016

208.43.224.240-static.reverse.softlayer.com
January 17, 2014

108.168.162.216-static.reverse.softlayer.com
January 17, 2014

208.43.244.224-static.reverse.softlayer.com
January 17, 2014

208.43.249.112-static.reverse.softlayer.com
January 17, 2014

50.97.40.168-static.reverse.softlayer.com
January 17, 2014

50.97.57.32-static.reverse.softlayer.com
January 17, 2014

50.97.56.104-static.reverse.softlayer.com
January 17, 2014

184.173.139.224-static.reverse.softlayer.com
January 17, 2014

208.43.236.200-static.reverse.softlayer.com
January 17, 2014

208.43.230.160-static.reverse.softlayer.com
January 17, 2014

File downloads found at URLs served by www.performersoft.com.

1 / 68      (PUP)
http://www.performersoft.com/.../PCPerformer_inc.exe  (4cab09711a13249c270035f708eb0dfd)

12 / 68    (Adware)

17 / 68    (PUP)
http://www.performersoft.com/.../DriverPerformer_J.exe  (9119a79b4fca83effc0193ea21b9a6a2)

9 / 68      (PUP)
http://www.performersoft.com/.../pcperformer_st.exe  (install pc performer153218.exe)

26 / 68    (PUP)
http://www.performersoft.com/.../PCPerformer_inc.exe  (b8922dfbf6e97834c12098c5fb1c824f)

3 / 68      (Adware)

9 / 68      (PUP)

26 / 68    (PUP)

1 / 68      (PUP)
http://www.performersoft.com/.../PCPerformer_J13o.exe  (c576451696baabc76e5eb2c8c84b046e)

The following 4 files have been seen to comunicate with www.performersoft.com in live environments.

URL:
http://www.performersoft.com/

Google Analytics:
UA-42277600

Title:
“PerformerSoft”

Web server:
nginx (PHP/5.4.17)

Facebook:
Likes:  12,929
Shares:  45
Comments:  8

Statistics are for the previous month.