gimp.soft32.com

I.T.N.T. SRL

Domain Information

The domain gimp.soft32.com registered by I.T.N.T. SRL was initially registered in September of 2003 through ENOM, INC.. The domain hosts various software downloads. The hosted servers are located in Ashburn, Virginia within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Monday, September 29, 2003

Expires date:
Sunday, September 29, 2024

Updated date:
Monday, October 06, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (93% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.Installer.ITNTSRL.K, PUP.Installer.ZuluSoftSRL.K, PUP.Downloader.Bundler.Soft32 (M), PUP.Downloader.Bundler.Soft32.Installer (M)
100.00%

Malwarebytes
PUP.Optional.Soft32.A
30.77%

Dr.Web
Adware.Downware.971, Adware.Downware.2152
30.77%

VIPRE Antivirus
Soft32Downloader, Threat.4783370
30.77%

ESET NOD32
MSIL/Soft32Downloader (variant)
23.08%

NANO AntiVirus
Riskware.Nsis.Downloader.cvxhzw
23.08%

herdProtect (fuzzy)
a variant of 53af70fd511d0c1bc383d7cdbf242a822d1321eb, a variant of f758ce35c0c4baac3245c54806bb0fec598cecca
15.38%

Trend Micro House Call
TROJ_GE.D6E51D90, Suspici.F72B5B4F
15.38%

avast!
Win32:PUP-gen [PUP]
7.69%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud)
7.69%

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
7.69%

ESET NOD32
MSIL/Soft32Downloader.C potentially unwanted application
7.69%

McAfee
SoftDropper
7.69%

Agnitum Outpost
PUA.Soft32Downloader
7.69%

Avira AntiVirus
APPL/Downloader.Gen
7.69%

The domain gimp.soft32.com has been seen to resolve to the following 34 IP addresses.

server-52-84-127-87.iad16.r.cloudfront.net
September 18, 2016

server-52-84-127-85.iad16.r.cloudfront.net
September 18, 2016

server-52-84-127-68.iad16.r.cloudfront.net
September 18, 2016

server-52-84-127-236.iad16.r.cloudfront.net
September 18, 2016

server-52-84-127-224.iad16.r.cloudfront.net
September 18, 2016

server-52-84-127-205.iad16.r.cloudfront.net
September 18, 2016

server-52-84-127-182.iad16.r.cloudfront.net
September 18, 2016

server-52-84-127-96.iad16.r.cloudfront.net
September 18, 2016

server-54-192-192-90.iad53.r.cloudfront.net
September 16, 2016

server-54-192-192-54.iad53.r.cloudfront.net
September 16, 2016

server-54-192-192-38.iad53.r.cloudfront.net
September 16, 2016

server-54-192-192-29.iad53.r.cloudfront.net
September 16, 2016

server-54-192-192-199.iad53.r.cloudfront.net
September 16, 2016

server-54-192-192-161.iad53.r.cloudfront.net
September 16, 2016

server-54-192-192-123.iad53.r.cloudfront.net
September 16, 2016

server-54-192-192-108.iad53.r.cloudfront.net
September 16, 2016

server-52-84-127-226.iad16.r.cloudfront.net
July 28, 2016

server-52-84-127-192.iad16.r.cloudfront.net
July 28, 2016

server-52-84-127-181.iad16.r.cloudfront.net
July 28, 2016

server-52-84-127-177.iad16.r.cloudfront.net
July 28, 2016

server-52-84-127-124.iad16.r.cloudfront.net
July 28, 2016

server-52-84-127-75.iad16.r.cloudfront.net
July 28, 2016

server-52-84-127-60.iad16.r.cloudfront.net
July 28, 2016

server-52-84-127-29.iad16.r.cloudfront.net
July 28, 2016

February 24, 2016

June 30, 2015

June 30, 2015

August 13, 2014

August 13, 2014

a23-67-242-43.deploy.static.akamaitechnologies.com
May 1, 2014

 
Showing 30 of 34 IP Addresses

File downloads found at URLs served by gimp.soft32.com.

The following 591 files have been seen to comunicate with gimp.soft32.com in live environments.

 
Latest 20 of 613 files

URL:
http://gimp.soft32.com/

Google Analytics:
UA-110868

Title:
“Download GIMP 2.8.10”

Description:
“GIMP free download. Get the latest version now. GIMP is a versatile graphics manipulation package.”

Network:
Amazon Cloudfront

Web server:
nginx

Facebook:
Likes:  3
Shares:  6
Comments:  1

Statistics are for the previous month.