The domain www.soft-ware.net registered by Soft-Ware International Ltd. was initially registered in March of 1999 through MESH DIGITAL LIMITED. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Nuremberg, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrant:
Soft-Ware International Ltd.
Registrar:
MESH DIGITAL LIMITED
Server location:
Bayern, Germany (DE)
Create date:
Wednesday, March 3, 1999
Expires date:
Friday, March 3, 2017
Updated date:
Tuesday, March 29, 2016
ASN:
AS24940 HETZNER-AS Hetzner Online AG
Scanner detections:
Detections (88% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.OpenCandy.Installer (L), PUP.Installer.ClientConnect.N, PUP.Installer.ClientConnect.L, PUP.Installer.ClientConnect.R, PUP.Installer.ClientConnect.P, PUP.STMSetup.Q, PUP.CyberservicesBV.N, PUP.Installer.CyberservicesBV.M, PUP.CyberservicesBV.S, PUP.Bundler.Covus, PUP.Installer.Conduit, PUP.Covus.FreemiumGmbH.Bundler (M), PUP.Covus.Freemium.Bundler (M), PUP.Outbrowse.CyberservicesBV.Bundler (M), PUP.Conduit.Bundler (M), PUP.InstallShare.REMedia (M), PUP.Outbrowse.Cyberser.Bundler (M), PUP.InstallShare.REMediaU.Installer (M), PUP.Conduit.ClientCo.Installer (M), PUP.Covus.HEYDAYEN.Bundler (M), PUP.Covus (M), PUP.Outbrowse (M), PUP.Conduit (M)
100.00%
Dr.Web
Adware.Conduit.96, Adware.Conduit.6, Adware.Conduit.3, Adware.Conduit.87, Adware.InstallCore.386, Trojan.Packed, Adware.Downware.10580, Adware.Downware.9982
53.49%
Malwarebytes
PUP.Optional.Conduit.A, PUP.Optional.InstallCore, PUP.Optional.Eguide, PUP.Optional.DownloadGuide, PUP.Optional.ClientConnect, PUP.Optional.OpenCandy
48.84%
VIPRE Antivirus
Threat.4786236, Conduit, Threat.5063361, Threat.4150696
41.86%
AVG
Generic, Covusfreemium, Cyberservices
39.53%
ESET NOD32
Win32/Toolbar.Conduit.AB potentially unwanted application, Win32/ClientConnect.A potentially unwanted application, Win32/InstallCore.PO potentially unwanted application
30.23%
avast!
Win32:Adware-BRM [PUP], Win32:DownloadGuide-H [PUP], Win32:Dropper-gen [Drp]
27.91%
Fortinet FortiGate
Riskware/Toolbar_Conduit, Riskware/Wajam, Riskware/ClientConnect, Riskware/Agent
27.91%
K7 AntiVirus
Trojan , Unwanted-Program
27.91%
ESET NOD32
Win32/OpenCandy, Win32/Wajam (variant), Win32/Toolbar.Conduit.AE, Win32/ClientConnect (variant), Win32/DownloadGuide (variant)
25.58%
Trend Micro House Call
TROJ_GE.4DCE9EB6, TROJ_GEN.F47V0311, TROJ_GEN.F47V0315, TROJ_GEN.F47V0222, Suspicious_GEN.F47V0730, TROJ_GEN.F47V1211, TROJ_GEN.F47V1219
25.58%
Agnitum Outpost
PUA.Toolbar.Conduit, Riskware.Agent
18.60%
NANO AntiVirus
Riskware.Win32.Conduit.dbqqxi, Riskware.Text.Drop.deoygt, Trojan.Win32.MLW.divivp, Trojan.Win32.DownloadGuide.dmhvci, Trojan.Win32.DownloadHelper.dormjw
18.60%
Kaspersky
not-a-virus:WebToolbar.Win32.Agent, not-a-virus:Downloader.Win32.DownloadHelper, not-a-virus:AdWare.Win32.Amonetize
16.28%
herdProtect (fuzzy)
a variant of 84178476c51a962ecad1b0ecb13581ceb87e0998, a variant of 314b064f2dc4681b90c47907444bb9fa8c0916f6, a variant of 8a35d593ba83f74cb3adad47a0c2b0a8d84ec40c
11.63%
The domain www.soft-ware.net has been seen to resolve to the following 4 IP addresses.
static.144.96.251.148.clients.your-server.de
April 13, 2014
static.212.75.9.5.clients.your-server.de
February 20, 2014
File downloads found at URLs served by www.soft-ware.net.
Latest 30 of 64 download URLs
The following 4 files have been seen to comunicate with www.soft-ware.net in live environments.
URL:
http://www.soft-ware.net/
Google Analytics:
UA-27019610
Title:
“SOFTWARE Download - Freeware - Shareware - Open Source - Soft-Ware.net”
Description:
“5.000 Programme für Windows zum kostenlosen Download. Übersichtlich nach Rubriken geordnet - mit ausführlichen Beschreibungen. Freeware - Shareware - Open Source.”
Facebook:
Likes: 10
Shares: 37
Comments: 8
Statistics are for the previous month.