The domain www.winsoftfirst.com registered by Mariah Walsh was initially registered in September of 2014 through NAME.COM, INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network.
Server location:
Northern Ireland, United Kingdom (GB)
Create date:
Tuesday, September 30, 2014
Expires date:
Friday, September 30, 2016
Updated date:
Thursday, November 12, 2015
Scanner detections:
Detections (98% detected)
Scan engine
Details
Detections
Reason Heuristics
Threat.Win.Reputation.IMP, PUP.Installer.PluginUpdateSL.F, PUP.Optional.Installer.F, PUP.Installer.LionSea, Threat.Softpulse.Bundler, PUP.Softpulse.PluginUpdate.Bundler (M), PUP.Adknowledge.Fileangels.Bundler (M), PUP.Adknowledge.SafeDown.Bundler (M), PUP.Air.Bundler.Installer.Meta (M), PUP.Softpulse.PluginUp.Bundler (M), PUP.Softpulse (M)
100.00%
Dr.Web
Trojan.DownLoader11.36367, Trojan.DownLoader11.36013, Program.Unwanted.79, Adware.SoftPules.3, Trojan.Domaiq.1, Adware.iBryte.486
25.00%
Kaspersky
Trojan.Win32.Buzus, not-a-virus:Downloader.Win32.LMN, not-a-virus:AdWare.Win32.SoftPulse, Trojan.Win32.Badur, not-a-virus:AdWare.Win32.iBryte
20.83%
VIPRE Antivirus
Threat.4783235, Threat.4150696, Threat.4778314
20.83%
McAfee
Socrydo, SoftPulse, Program.SoftPulse, Softpulse.a, IBryte-FRT, IBryte-FRK
20.83%
Malwarebytes
PUP.Optional.DomaIQ, PUP.Optional.OptimunInstaller
20.83%
K7 AntiVirus
Unwanted-Program , Trojan
20.83%
Bitdefender
Gen:Variant.Application.Bundler.SoftPulse.2, Adware.Agent.OLP, Gen:Variant.Adware.Kazy.466111, Gen:Variant.Application.Graftor.152464
20.83%
NANO AntiVirus
Trojan.Win32.LMN.dgkmmt, Trojan.Win32.SoftPulse.dfwfat, Riskware.Win32.SoftPulse.dgqttv, Riskware.Win32.IBryte.desauy
20.83%
Sophos
SoftPulse, PUA 'SoftPulse' (of type Adware), iBryte Premium Installer, iBryte Optimum Installer
20.83%
Avira AntiVirus
TR/Dropper.Gen, APPL/Softpulse.Gen8, TR/Trash.Gen, APPL/Softpulse.aone, ADWARE/iBryte.Gen4, ADWARE/iBryte.Gen7
20.83%
G Data
Gen:Variant.Application.Bundler.SoftPulse, Adware.Agent.OLP, Win32.Adware.IBryte, Gen:Variant.Application.Graftor.152464
20.83%
Vba32 AntiVirus
BScope.Adware.Softpulse, Trojan.Buzus, Downloader.LMN, AdWare.iBryte
20.83%
AVG
Generic, Adware BundleApp_r.AW, AdPlugin, Adware AdPlugin
20.83%
avast!
Win32:SoftPulse-AK [PUP], Win32:PUP-gen [PUP], Win32:SoftPulse-AJ [PUP], Win32:GenMalicious-ADB [PUP], Win32:Adware-gen [Adw]
20.83%
The domain www.winsoftfirst.com has been seen to resolve to the following 8 IP addresses.
softboxy.com
December 15, 2015
unallocated.barefruit.co.uk
May 4, 2015
ec2-54-191-146-90.us-west-2.compute.amazonaws.com
November 10, 2014
ec2-54-69-98-117.us-west-2.compute.amazonaws.com
November 10, 2014
ec2-54-186-254-153.us-west-2.compute.amazonaws.com
October 24, 2014
ec2-54-186-247-123.us-west-2.compute.amazonaws.com
October 24, 2014
File downloads found at URLs served by www.winsoftfirst.com.
Latest 30 of 49 download URLs
The following 230 files have been seen to comunicate with www.winsoftfirst.com in live environments.
URL:
http://www.winsoftfirst.com/