www.winsoftfirst.com

Mariah Walsh

Domain Information

The domain www.winsoftfirst.com registered by Mariah Walsh was initially registered in September of 2014 through NAME.COM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Registrar:
NAME.COM, INC.

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Tuesday, September 30, 2014

Expires date:
Friday, September 30, 2016

Updated date:
Thursday, November 12, 2015

Root domain:

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP, PUP.Installer.PluginUpdateSL.F, PUP.Optional.Installer.F, PUP.Installer.LionSea, Threat.Softpulse.Bundler, PUP.Softpulse.PluginUpdate.Bundler (M), PUP.Adknowledge.Fileangels.Bundler (M), PUP.Adknowledge.SafeDown.Bundler (M), PUP.Air.Bundler.Installer.Meta (M), PUP.Softpulse.PluginUp.Bundler (M), PUP.Softpulse (M)
100.00%

Dr.Web
Trojan.DownLoader11.36367, Trojan.DownLoader11.36013, Program.Unwanted.79, Adware.SoftPules.3, Trojan.Domaiq.1, Adware.iBryte.486
25.00%

Kaspersky
Trojan.Win32.Buzus, not-a-virus:Downloader.Win32.LMN, not-a-virus:AdWare.Win32.SoftPulse, Trojan.Win32.Badur, not-a-virus:AdWare.Win32.iBryte
20.83%

VIPRE Antivirus
Threat.4783235, Threat.4150696, Threat.4778314
20.83%

McAfee
Socrydo, SoftPulse, Program.SoftPulse, Softpulse.a, IBryte-FRT, IBryte-FRK
20.83%

Malwarebytes
PUP.Optional.DomaIQ, PUP.Optional.OptimunInstaller
20.83%

K7 AntiVirus
Unwanted-Program , Trojan
20.83%

Bitdefender
Gen:Variant.Application.Bundler.SoftPulse.2, Adware.Agent.OLP, Gen:Variant.Adware.Kazy.466111, Gen:Variant.Application.Graftor.152464
20.83%

NANO AntiVirus
Trojan.Win32.LMN.dgkmmt, Trojan.Win32.SoftPulse.dfwfat, Riskware.Win32.SoftPulse.dgqttv, Riskware.Win32.IBryte.desauy
20.83%

Sophos
SoftPulse, PUA 'SoftPulse' (of type Adware), iBryte Premium Installer, iBryte Optimum Installer
20.83%

Avira AntiVirus
TR/Dropper.Gen, APPL/Softpulse.Gen8, TR/Trash.Gen, APPL/Softpulse.aone, ADWARE/iBryte.Gen4, ADWARE/iBryte.Gen7
20.83%

G Data
Gen:Variant.Application.Bundler.SoftPulse, Adware.Agent.OLP, Win32.Adware.IBryte, Gen:Variant.Application.Graftor.152464
20.83%

Vba32 AntiVirus
BScope.Adware.Softpulse, Trojan.Buzus, Downloader.LMN, AdWare.iBryte
20.83%

AVG
Generic, Adware BundleApp_r.AW, AdPlugin, Adware AdPlugin
20.83%

avast!
Win32:SoftPulse-AK [PUP], Win32:PUP-gen [PUP], Win32:SoftPulse-AJ [PUP], Win32:GenMalicious-ADB [PUP], Win32:Adware-gen [Adw]
20.83%

The domain www.winsoftfirst.com has been seen to resolve to the following 8 IP addresses.

softboxy.com
December 15, 2015

unallocated.barefruit.co.uk
May 4, 2015

ec2-54-191-146-90.us-west-2.compute.amazonaws.com
November 10, 2014

ec2-54-69-98-117.us-west-2.compute.amazonaws.com
November 10, 2014

ec2-54-186-254-153.us-west-2.compute.amazonaws.com
October 24, 2014

ec2-54-186-247-123.us-west-2.compute.amazonaws.com
October 24, 2014

October 20, 2014

October 20, 2014

File downloads found at URLs served by www.winsoftfirst.com.

 
Latest 30 of 49 download URLs

The following 230 files have been seen to comunicate with www.winsoftfirst.com in live environments.

 
Latest 20 of 230 files

URL:
http://www.winsoftfirst.com/

Title:
“SES-15”

Web server:
Apache