xplode-soft.com

Ivan Zaycev

Domain Information

The domain xplode-soft.com registered by Ivan Zaycev was initially registered in July of 2014 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, LLC

Server location:
Arizona, United States (US)

Create date:
Monday, July 21, 2014

Expires date:
Tuesday, July 21, 2015

Updated date:
Thursday, April 23, 2015

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.InformationTechnologySystems.R, PUP.installCore.InformationTechnologySystems.Installer (M), PUP.installCore.Informat.Installer (M), PUP.installCore (M)
100.00%

Avira AntiVirus
ADWARE/InstallCore.Gen9
64.71%

Malwarebytes
PUP.Optional.Downloader
58.82%

ESET NOD32
Win32/InstallCore.PX potentially unwanted application, Win32/InstallCore.UE potentially unwanted application
58.82%

Dr.Web
Trojan.Packed.28409
58.82%

K7 AntiVirus
Trojan
58.82%

SUPERAntiSpyware
PUP.InstallCore/Variant
58.82%

AVG
Generic
58.82%

VIPRE Antivirus
Threat.4150696
58.82%

F-Prot
W32/InstallCore.AC.gen
58.82%

McAfee
Trojan.Artemis!460ECEB35134
58.82%

Clam AntiVirus
Win.Trojan.Installcore-231
52.94%

NANO AntiVirus
Riskware.Win32.InstallCore.dfgmcg, Riskware.Win32.InstallCore.dfgmnf
52.94%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
47.06%

Sophos
PUA 'Install Core Click run software'
47.06%

The domain xplode-soft.com has been seen to resolve to the following 2 IP addresses.

ip-184-168-221-56.ip.secureserver.net
March 9, 2015

September 7, 2014

File downloads found at URLs served by xplode-soft.com.

The following 119 files have been seen to comunicate with xplode-soft.com in live environments.

 
Latest 20 of 120 files

URL:
http://xplode-soft.com/

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)

30 of 44 related domains