bbp.softobase.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain bbp.softobase.com is registered by proxy through ENOM, INC. and was originally registered in April of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Gunzenhausen, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
ENOM, INC.

Server location:
Bayern, Germany (DE)

Create date:
Wednesday, April 18, 2012

Expires date:
Sunday, April 18, 2021

Updated date:
Friday, March 25, 2016

ASN:
AS24940 HETZNER-AS Hetzner Online AG,DE

Root domain:

Scanner detections:
Detections  (75% detected)

Scan engine
Details
Detections

Clam AntiVirus
Win.Trojan.Agent-906217
100.00%

Kaspersky
not-a-virus:HEUR:Downloader.NSIS.SoftBase
100.00%

NANO AntiVirus
Riskware.Nsis.Downware.dvdoyv
100.00%

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF[F1]
100.00%

Dr.Web
Adware.Downware.11495
100.00%

Avira AntiVirus
PUA/Softobase.Gen
100.00%

Panda Antivirus
Generic Suspicious
100.00%

AVG
Generic
100.00%

Reason Heuristics
PUP.INSITEGROUP.Installer (M), PUP.INSITEGR.Installer (M)
100.00%

Bkav FE
W32.HfsAdware
66.67%

K7 AntiVirus
Unwanted-Program
66.67%

ESET NOD32
Win32/Softobase.D potentially unwanted
66.67%

Trend Micro
TROJ_GEN.R0EAC0OHO15
66.67%

G Data
Win32.Trojan.Agent.BF7QC1
66.67%

McAfee
Artemis!C0C7E1348710
66.67%

The domain bbp.softobase.com has been seen to resolve to the following 3 IP addresses.

85-10-200-21.clients.your-server.de
October 13, 2015

static.85-10-196-94.clients.your-server.de
October 13, 2015

static.158.40.63.178.clients.your-server.de
October 13, 2015

File downloads found at URLs served by bbp.softobase.com.

1 / 68      (Adware)
http://bbp.softobase.com/.../KMPlayer.exe  (d7fd500cdf192d131064d780399531e4)

30 / 68    (Adware)
http://bbp.softobase.com/.../Opera.exe  (c0c7e13487104e55232e3b13c3d7f48a)

0 / 68
http://bbp.softobase.com/uTorrent.exe  (be19f180abe2d1d6c04f639e57c59ba4)

11 / 68    (Adware)
http://bbp.softobase.com/.../KLiteCodecPackFull.exe  (5d6325889c6584f02efe72c4eb40669f)

The following 7 files have been seen to comunicate with bbp.softobase.com in live environments.

URL:
http://bbp.softobase.com/

Web server:
nginx/1.8.0