facebook-messenger.soft32.com

I.T.N.T. SRL

Domain Information

The domain facebook-messenger.soft32.com registered by I.T.N.T. SRL was initially registered in September of 2003 through ENOM, INC.. The domain hosts various software downloads. The hosted servers are located in Seattle, Washington within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).

This Soft32 domain (part of the Soft32.com site) displays information for the software program facebook messenger as well as provides 'free' downloads managed through the Soft32's Download Manager (which might include potentially unwanted offers such as the AVG Toolbar).
Registrar:
ENOM, INC.

Server location:
Washington, United States (US)

Create date:
Monday, September 29, 2003

Expires date:
Sunday, September 29, 2024

Updated date:
Friday, December 11, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc., US

Root domain:

Scanner detections:
Detections  (93% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Downloader.Bundler.Soft32.Installer (M), PUP.Downloader.Bundler.Soft32 (M)
93.33%

Malwarebytes
Trojan.Agent
6.67%

XVirus List
Win.Detected
6.67%

The domain facebook-messenger.soft32.com has been seen to resolve to the following 26 IP addresses.

server-52-84-127-164.iad16.r.cloudfront.net
August 12, 2016

server-52-84-127-96.iad16.r.cloudfront.net
August 12, 2016

server-52-84-127-32.iad16.r.cloudfront.net
August 12, 2016

server-52-84-127-14.iad16.r.cloudfront.net
August 12, 2016

server-52-84-127-13.iad16.r.cloudfront.net
August 12, 2016

server-52-84-127-214.iad16.r.cloudfront.net
August 12, 2016

server-52-84-127-199.iad16.r.cloudfront.net
August 12, 2016

server-52-84-127-172.iad16.r.cloudfront.net
August 12, 2016

server-52-84-127-42.iad16.r.cloudfront.net
August 7, 2016

server-52-84-127-11.iad16.r.cloudfront.net
August 7, 2016

server-52-84-127-174.iad16.r.cloudfront.net
August 7, 2016

server-52-84-127-151.iad16.r.cloudfront.net
August 7, 2016

server-52-84-127-137.iad16.r.cloudfront.net
August 7, 2016

server-52-84-127-131.iad16.r.cloudfront.net
August 7, 2016

server-52-84-127-45.iad16.r.cloudfront.net
August 7, 2016

server-52-84-127-60.iad16.r.cloudfront.net
July 30, 2016

server-52-84-127-29.iad16.r.cloudfront.net
July 30, 2016

server-52-84-127-226.iad16.r.cloudfront.net
July 30, 2016

server-52-84-127-192.iad16.r.cloudfront.net
July 30, 2016

server-52-84-127-181.iad16.r.cloudfront.net
July 30, 2016

server-52-84-127-177.iad16.r.cloudfront.net
July 30, 2016

server-52-84-127-124.iad16.r.cloudfront.net
July 30, 2016

server-52-84-127-75.iad16.r.cloudfront.net
July 30, 2016

April 14, 2016

December 25, 2015

December 25, 2015

File downloads found at URLs served by facebook-messenger.soft32.com.

1 / 68      (Adware)

2 / 68
http://facebook-messenger.soft32.com/get/file/id/.../  (facebookmessengersetup_v122050.exe)

The following 7 files have been seen to comunicate with facebook-messenger.soft32.com in live environments.

URL:
http://facebook-messenger.soft32.com/

Google Analytics:
UA-110868

Title:
“Download Facebook Messenger 3.0”

Description:
“Facebook Messenger free download. Get the latest version now. Keep up with friends, no matter what you're doing.”

Network:
Amazon Cloudfront

Web server:
nginx

Facebook:
Likes:  48
Shares:  12
Comments:  1

Statistics are for the previous month.