ammyy-admin.soft32.com

I.T.N.T. SRL

Domain Information

The domain ammyy-admin.soft32.com registered by I.T.N.T. SRL was initially registered in September of 2003 through ENOM, INC.. The domain hosts various software downloads. The hosted servers are located in Dulles, Virginia within the United States. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).

This Soft32 domain (part of the Soft32.com site) displays information for the software program ammyy admin as well as provides 'free' downloads managed through the Soft32's Download Manager (which might include potentially unwanted offers such as the AVG Toolbar).
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Monday, September 29, 2003

Expires date:
Sunday, September 29, 2024

Updated date:
Friday, December 11, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc., US

Root domain:

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Service.Ammyy.G, PUP.Installer.ZuluSoftSRL.R, PUP.Ammyy, PUP.Downloader.Bundler.Soft32.Installer (M), PUP.WeDownload.Bundler (M), Threat.Win.Reputation.IMP, PUP.Downloader.Bundler.Soft32 (M)
97.78%

Dr.Web
Program.RemoteAdmin.701, Adware.Downware.2152
8.89%

NANO AntiVirus
Trojan.Win32.RemoteAdmin.cqzmlg, Riskware.Nsis.Downloader.cvxhzw
6.67%

Avira AntiVirus
SPR/RemoteAdmin.C.1, APPL/Downloader.Gen
6.67%

McAfee
Artemis!0ECDB503FCA9, SoftDropper
6.67%

VIPRE Antivirus
Remote-Access.Win32.Ammyy, Threat.4783370
6.67%

ESET NOD32
Win32/RemoteAdmin.Ammyy (variant)
4.44%

Trend Micro House Call
TROJ_GEN.R0C1H07BC14, Suspicious_GEN.F47V0123
4.44%

Baidu Antivirus
Hacktool.Win32.RemoteAdmin, Hacktool.Win32.AmmyyAdmin
4.44%

ESET NOD32
MSIL/Soft32Downloader.C potentially unwanted application
4.44%

Malwarebytes
PUP.Optional.Soft32.A
4.44%

Agnitum Outpost
PUA.Soft32Downloader
4.44%

Microsoft Security Essentials
Worm:Win32/NeksMiner.A
2.22%

F-Secure
Application:W32/Generic.70053c248f!Online
2.22%

Bkav FE
W32.Clodaa2.Trojan
2.22%

The domain ammyy-admin.soft32.com has been seen to resolve to the following 67 IP addresses.

server-54-192-192-161.iad53.r.cloudfront.net
September 16, 2016

server-54-192-192-114.iad53.r.cloudfront.net
September 14, 2016

server-54-192-192-108.iad53.r.cloudfront.net
September 14, 2016

server-52-84-127-68.iad16.r.cloudfront.net
September 13, 2016

server-52-84-127-20.iad16.r.cloudfront.net
September 13, 2016

server-52-84-127-236.iad16.r.cloudfront.net
September 13, 2016

server-52-84-127-224.iad16.r.cloudfront.net
September 13, 2016

server-52-84-127-112.iad16.r.cloudfront.net
September 13, 2016

server-52-84-127-105.iad16.r.cloudfront.net
September 13, 2016

server-52-84-127-87.iad16.r.cloudfront.net
September 13, 2016

server-52-84-127-85.iad16.r.cloudfront.net
September 13, 2016

server-54-192-192-54.iad53.r.cloudfront.net
September 13, 2016

server-54-192-192-38.iad53.r.cloudfront.net
September 13, 2016

server-54-192-192-29.iad53.r.cloudfront.net
September 13, 2016

server-54-192-192-15.iad53.r.cloudfront.net
September 13, 2016

server-54-192-192-125.iad53.r.cloudfront.net
September 13, 2016

server-54-192-192-90.iad53.r.cloudfront.net
September 13, 2016

server-54-192-192-24.iad53.r.cloudfront.net
September 4, 2016

server-54-192-192-205.iad53.r.cloudfront.net
September 4, 2016

server-54-192-192-199.iad53.r.cloudfront.net
September 4, 2016

server-54-192-192-179.iad53.r.cloudfront.net
September 4, 2016

server-54-192-192-123.iad53.r.cloudfront.net
September 4, 2016

server-54-192-192-97.iad53.r.cloudfront.net
September 4, 2016

server-54-192-192-87.iad53.r.cloudfront.net
September 4, 2016

server-54-192-192-53.iad53.r.cloudfront.net
September 4, 2016

server-52-84-127-238.iad16.r.cloudfront.net
August 31, 2016

server-52-84-127-161.iad16.r.cloudfront.net
August 31, 2016

server-52-84-127-157.iad16.r.cloudfront.net
August 31, 2016

server-52-84-127-185.iad16.r.cloudfront.net
August 28, 2016

server-52-84-127-171.iad16.r.cloudfront.net
August 28, 2016

 
Showing 30 of 67 IP Addresses

File downloads found at URLs served by ammyy-admin.soft32.com.

1 / 68      (Adware)

1 / 68      (Adware)

2 / 68      (false positives)

1 / 68      (Malware)

5 / 68      (PUP)

 
Latest 30 of 47 download URLs

The following 61 files have been seen to comunicate with ammyy-admin.soft32.com in live environments.

 
Latest 20 of 137 files

URL:
http://ammyy-admin.soft32.com/

Google Analytics:
UA-110868

Title:
“Download Ammyy Admin 3.5”

Description:
“Ammyy Admin free download. Get the latest version now. Ammyy Admin - is a free remote desktop sharing and PC remote control software.”

Network:
Amazon Cloudfront

Web server:
nginx

Facebook:
Likes:  76
Shares:  13
Comments:  2

Statistics are for the previous month.