www.soft-ware.net

Soft-Ware International Ltd.

Domain Information

The domain www.soft-ware.net registered by Soft-Ware International Ltd. was initially registered in March of 1999 through MESH DIGITAL LIMITED. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Nuremberg, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
MESH DIGITAL LIMITED

Server location:
Bayern, Germany (DE)

Create date:
Wednesday, March 3, 1999

Expires date:
Friday, March 3, 2017

Updated date:
Tuesday, March 29, 2016

ASN:
AS24940 HETZNER-AS Hetzner Online AG

Root domain:

Scanner detections:
Detections  (88% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.OpenCandy.Installer (L), PUP.Installer.ClientConnect.N, PUP.Installer.ClientConnect.L, PUP.Installer.ClientConnect.R, PUP.Installer.ClientConnect.P, PUP.STMSetup.Q, PUP.CyberservicesBV.N, PUP.Installer.CyberservicesBV.M, PUP.CyberservicesBV.S, PUP.Bundler.Covus, PUP.Installer.Conduit, PUP.Covus.FreemiumGmbH.Bundler (M), PUP.Covus.Freemium.Bundler (M), PUP.Outbrowse.CyberservicesBV.Bundler (M), PUP.Conduit.Bundler (M), PUP.InstallShare.REMedia (M), PUP.Outbrowse.Cyberser.Bundler (M), PUP.InstallShare.REMediaU.Installer (M), PUP.Conduit.ClientCo.Installer (M), PUP.Covus.HEYDAYEN.Bundler (M), PUP.Covus (M), PUP.Outbrowse (M), PUP.Conduit (M)
100.00%

Dr.Web
Adware.Conduit.96, Adware.Conduit.6, Adware.Conduit.3, Adware.Conduit.87, Adware.InstallCore.386, Trojan.Packed, Adware.Downware.10580, Adware.Downware.9982
53.49%

Malwarebytes
PUP.Optional.Conduit.A, PUP.Optional.InstallCore, PUP.Optional.Eguide, PUP.Optional.DownloadGuide, PUP.Optional.ClientConnect, PUP.Optional.OpenCandy
48.84%

VIPRE Antivirus
Threat.4786236, Conduit, Threat.5063361, Threat.4150696
41.86%

AVG
Generic, Covusfreemium, Cyberservices
39.53%

ESET NOD32
Win32/Toolbar.Conduit.AB potentially unwanted application, Win32/ClientConnect.A potentially unwanted application, Win32/InstallCore.PO potentially unwanted application
30.23%

avast!
Win32:Adware-BRM [PUP], Win32:DownloadGuide-H [PUP], Win32:Dropper-gen [Drp]
27.91%

Fortinet FortiGate
Riskware/Toolbar_Conduit, Riskware/Wajam, Riskware/ClientConnect, Riskware/Agent
27.91%

K7 AntiVirus
Trojan , Unwanted-Program
27.91%

ESET NOD32
Win32/OpenCandy, Win32/Wajam (variant), Win32/Toolbar.Conduit.AE, Win32/ClientConnect (variant), Win32/DownloadGuide (variant)
25.58%

Trend Micro House Call
TROJ_GE.4DCE9EB6, TROJ_GEN.F47V0311, TROJ_GEN.F47V0315, TROJ_GEN.F47V0222, Suspicious_GEN.F47V0730, TROJ_GEN.F47V1211, TROJ_GEN.F47V1219
25.58%

Agnitum Outpost
PUA.Toolbar.Conduit, Riskware.Agent
18.60%

NANO AntiVirus
Riskware.Win32.Conduit.dbqqxi, Riskware.Text.Drop.deoygt, Trojan.Win32.MLW.divivp, Trojan.Win32.DownloadGuide.dmhvci, Trojan.Win32.DownloadHelper.dormjw
18.60%

Kaspersky
not-a-virus:WebToolbar.Win32.Agent, not-a-virus:Downloader.Win32.DownloadHelper, not-a-virus:AdWare.Win32.Amonetize
16.28%

herdProtect (fuzzy)
a variant of 84178476c51a962ecad1b0ecb13581ceb87e0998, a variant of 314b064f2dc4681b90c47907444bb9fa8c0916f6, a variant of 8a35d593ba83f74cb3adad47a0c2b0a8d84ec40c
11.63%

The domain www.soft-ware.net has been seen to resolve to the following 4 IP addresses.

April 6, 2016

April 6, 2016

static.144.96.251.148.clients.your-server.de
April 13, 2014

static.212.75.9.5.clients.your-server.de
February 20, 2014

File downloads found at URLs served by www.soft-ware.net.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

7 / 68      (PUP)
http://www.soft-ware.net/amr-mp3-converter/downloads/.../amrtomp3converter_setup.exe  (a5dd04c211caf1be8d4d50ca88d0e13f50784dbbef0aa653ef408fb6b2d26e62)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (PUP)

14 / 68    (Adware)
http://www.soft-ware.net/getfile/photofiltre/.../pf7-setup-en.exe  (0c8d1d6dd96155ee515c2eeee7ce94d07a3bb6e866d7324fd82daf139f0df9f8)

10 / 68    (PUP)
http://www.soft-ware.net/em-free-photo-collage/downloads/.../empc_setup.exe  (801674788d19c2a233279d66898c8c138408c234c05e826a1f6d86cb6a39c3a2)

1 / 68      (PUP)

14 / 68    (Adware)

7 / 68      (Adware)

7 / 68      (Adware)

 
Latest 30 of 64 download URLs

The following 4 files have been seen to comunicate with www.soft-ware.net in live environments.

URL:
http://www.soft-ware.net/

Google Analytics:
UA-27019610

Title:
“SOFTWARE Download - Freeware - Shareware - Open Source - Soft-Ware.net”

Description:
“5.000 Programme für Windows zum kostenlosen Download. Übersichtlich nach Rubriken geordnet - mit ausführlichen Beschreibungen. Freeware - Shareware - Open Source.”

Web server:
nginx

Facebook:
Likes:  10
Shares:  37
Comments:  8

Statistics are for the previous month.