half-life-2-garrys-mod.soft32.com

I.T.N.T. SRL

Domain Information

The domain half-life-2-garrys-mod.soft32.com registered by I.T.N.T. SRL was initially registered in September of 2003 through ENOM, INC.. The domain hosts various software downloads. The hosted servers are located in Seattle, Washington within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).

This Soft32 domain (part of the Soft32.com site) displays information for the software program half life 2 garrys mod as well as provides 'free' downloads managed through the Soft32's Download Manager (which might include potentially unwanted offers such as the AVG Toolbar).
Registrar:
ENOM, INC.

Server location:
Washington, United States (US)

Create date:
Monday, September 29, 2003

Expires date:
Sunday, September 29, 2024

Updated date:
Monday, October 6, 2014

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
(M), PUP.Installer.ZuluSoftSRL.b, PUP.Downloader.Bundler.Soft32.Installer, PUP.Downloader.Bundler.Soft32.Installer (M), PUP.Downloader.Bundler.Soft32 (M)
100.00%

Malwarebytes
PUP.Optional.Soft32.A, PUP.Optional.Zulu
20.00%

NANO AntiVirus
Riskware.Nsis.Downloader.cvxhzw
20.00%

Dr.Web
Adware.Downware.2152, Adware.Downware.4350, Adware.Downware.8288, Adware.Downware.9728
20.00%

VIPRE Antivirus
Soft32Downloader, Threat.4783370, Threat.4150696
20.00%

ESET NOD32
MSIL/Soft32Downloader.C potentially unwanted application
17.78%

McAfee
SoftDropper, Program.SoftDropper, Artemis!E6A73348F0B6
15.56%

Avira AntiVirus
APPL/Downloader.Gen
15.56%

Agnitum Outpost
PUA.Soft32Downloader, PUA.Downware
13.33%

herdProtect (fuzzy)
a variant of 506cb5fd512e2434509dbcf01356c50b39ce62e6, a variant of f758ce35c0c4baac3245c54806bb0fec598cecca, a variant of f9186f12d1dd196b2e55041a6c8a8c38791b0a1d
8.89%

Trend Micro House Call
ADW_DOWNWARE.GC, Suspici.F72B5B4F
6.67%

Comodo Security
UnclassifiedMalware, Application.Win32.Kranet.K
4.44%

AVG
Generic
4.44%

ESET NOD32
MSIL/Soft32Downloader (variant)
2.22%

Trend Micro
ADW_DOWNWARE.GC
2.22%

The domain half-life-2-garrys-mod.soft32.com has been seen to resolve to the following 45 IP addresses.

server-52-84-127-87.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-85.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-68.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-236.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-224.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-205.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-182.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-188.iad16.r.cloudfront.net
August 19, 2016

server-52-84-127-152.iad16.r.cloudfront.net
August 19, 2016

server-52-84-127-141.iad16.r.cloudfront.net
August 19, 2016

server-52-84-127-136.iad16.r.cloudfront.net
August 19, 2016

server-52-84-127-60.iad16.r.cloudfront.net
August 19, 2016

server-52-84-127-48.iad16.r.cloudfront.net
August 19, 2016

server-52-84-127-40.iad16.r.cloudfront.net
August 19, 2016

server-52-84-127-200.iad16.r.cloudfront.net
August 19, 2016

server-52-85-142-209.iad12.r.cloudfront.net
August 14, 2016

server-52-85-142-70.iad12.r.cloudfront.net
August 14, 2016

server-52-85-142-46.iad12.r.cloudfront.net
August 14, 2016

server-52-85-142-43.iad12.r.cloudfront.net
August 14, 2016

server-52-85-142-36.iad12.r.cloudfront.net
August 14, 2016

server-52-85-142-12.iad12.r.cloudfront.net
August 14, 2016

server-52-85-142-254.iad12.r.cloudfront.net
August 14, 2016

server-52-85-142-229.iad12.r.cloudfront.net
August 14, 2016

server-52-84-127-164.iad16.r.cloudfront.net
August 8, 2016

server-52-84-127-96.iad16.r.cloudfront.net
August 8, 2016

server-52-84-127-32.iad16.r.cloudfront.net
August 8, 2016

server-52-84-127-14.iad16.r.cloudfront.net
August 8, 2016

server-52-84-127-13.iad16.r.cloudfront.net
August 8, 2016

server-52-84-127-214.iad16.r.cloudfront.net
August 8, 2016

server-52-84-127-199.iad16.r.cloudfront.net
August 8, 2016

 
Showing 30 of 45 IP Addresses

File downloads found at URLs served by half-life-2-garrys-mod.soft32.com.

1 / 68      (Adware)
http://half-life-2-garrys-mod.soft32.com/get/file/id/.../  (half life 2 garry 039 s mod setup.exe)

1 / 68      (Malware)

7 / 68      (Adware)

 
Latest 30 of 48 download URLs

The following 125 files have been seen to comunicate with half-life-2-garrys-mod.soft32.com in live environments.

 
Latest 20 of 140 files

URL:
http://half-life-2-garrys-mod.soft32.com/

Google Analytics:
UA-110868

Title:
“Download Half-Life 2 Garry's Mod 9.0.4”

Title (4/14/2014):
“Download Half-Life 2 Garry's Mod 9.0.4”

Title (8/10/2014):
“Download Half-Life 2 Garry's Mod 9.0.4”

Description:
“Half-Life 2 Garry's Mod free download. Get the latest version now. Garry's Mod for Half-Life 2 lets you take complete advantage of the physics system.”

Network:
Amazon Cloudfront

Web server:
nginx

Facebook:
Likes:  3

Statistics are for the previous month.