i.softplanet.com

Secure Download Ltd

Domain Information

The domain i.softplanet.com registered by Secure Download Ltd was initially registered in August of 1996 through WILD WEST DOMAINS, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Seattle, Washington within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
WILD WEST DOMAINS, LLC

Server location:
Washington, United States (US)

Create date:
Thursday, August 29, 1996

Expires date:
Sunday, August 28, 2022

Updated date:
Friday, May 10, 2013

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (62% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.AVSoftware EOOD, PUP.AVSoftware EOOD.SecureDownload, PUP.AVSoftware EOOD.SecureDownload (M), PUP.AVSoftware EOOD.SecureDownload.Installer (M), PUP.AVSoftware EOOD.SecureDo (M), PUP.AVSoftware EOOD.SecureDo.Installer (M), PUP.AVSoftware EOOD (M)
93.75%

Dr.Web
Adware.OpenCandy.39, Adware.Downware.11222, Trojan.Click3.11442, Trojan.Click3.11944
15.63%

AVG
Generic, Downloader
9.38%

McAfee Web Gateway
BehavesLike.Win32.Downloader.jc, Artemis
9.38%

avast!
Win32:Evo-gen [Susp], Win32:Rootkit-gen [Rtk]
6.25%

McAfee
Artemis!F19138054326, Artemis!DD62A6CDC508
6.25%

ByteHero BDV
Virus.Win32.Part.a
3.13%

ESET NOD32
Win32/OpenCandy (variant)
3.13%

VIPRE Antivirus
Trojan.Win32.Generic
3.13%

NANO AntiVirus
Trojan.Win32.CheatEngine.ddqnic
3.13%

Antiy Labs AVL
Trojan/Win32.Tgenic
3.13%

Avira AntiVirus
TR/Crypt.CFI.Gen
3.13%

Bkav FE
W32.Clod5a5.Trojan
3.13%

The domain i.softplanet.com has been seen to resolve to the following 501 IP addresses.

server-52-84-125-198.iad16.r.cloudfront.net
September 16, 2016

server-52-84-125-130.iad16.r.cloudfront.net
September 16, 2016

server-52-84-125-103.iad16.r.cloudfront.net
September 16, 2016

server-52-84-125-87.iad16.r.cloudfront.net
September 16, 2016

server-52-84-125-85.iad16.r.cloudfront.net
September 16, 2016

server-52-84-125-229.iad16.r.cloudfront.net
September 16, 2016

server-52-84-125-217.iad16.r.cloudfront.net
September 16, 2016

server-52-84-125-210.iad16.r.cloudfront.net
September 16, 2016

server-54-230-193-169.iad53.r.cloudfront.net
September 1, 2016

server-54-230-193-133.iad53.r.cloudfront.net
September 1, 2016

server-54-230-193-114.iad53.r.cloudfront.net
September 1, 2016

server-54-230-193-113.iad53.r.cloudfront.net
September 1, 2016

server-54-230-193-90.iad53.r.cloudfront.net
September 1, 2016

server-54-230-193-84.iad53.r.cloudfront.net
September 1, 2016

server-54-230-193-195.iad53.r.cloudfront.net
September 1, 2016

server-54-230-193-186.iad53.r.cloudfront.net
September 1, 2016

server-52-84-125-82.iad16.r.cloudfront.net
August 30, 2016

server-52-84-125-32.iad16.r.cloudfront.net
August 23, 2016

server-52-84-125-216.iad16.r.cloudfront.net
August 23, 2016

server-54-192-19-106.iad12.r.cloudfront.net
August 23, 2016

server-54-192-19-80.iad12.r.cloudfront.net
August 23, 2016

server-54-192-19-47.iad12.r.cloudfront.net
August 23, 2016

server-54-192-19-32.iad12.r.cloudfront.net
August 23, 2016

server-54-192-19-22.iad12.r.cloudfront.net
August 23, 2016

server-54-192-19-187.iad12.r.cloudfront.net
August 23, 2016

server-54-192-19-120.iad12.r.cloudfront.net
August 23, 2016

server-52-84-125-8.iad16.r.cloudfront.net
August 22, 2016

server-52-84-125-253.iad16.r.cloudfront.net
August 22, 2016

server-52-84-125-123.iad16.r.cloudfront.net
August 22, 2016

server-52-84-125-106.iad16.r.cloudfront.net
August 22, 2016

 
Showing 30 of 501 IP Addresses

File downloads found at URLs served by i.softplanet.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://i.softplanet.com/.../GIMP.2.8.14.exe  (91480da0f83b893b0aa32efb657487e2)

0 / 68

1 / 68      (Adware)
http://i.softplanet.com/.../Hola-Unblocker.1.3.137.exe  (c9c6c31b530cf0050d4de69fb6b78826)

1 / 68      (Adware)
http://i.softplanet.com/.../Spotify.0.9.13.24.exe  (5a97a2537f895731973c5da28d849c01)

1 / 68      (Adware)
http://i.softplanet.com/.../Java.820.exe  (989560ed39163e8652c96e9c2b10dce7)

1 / 68      (Adware)

1 / 68      (Adware)

2 / 68      (Adware)
http://i.softplanet.com/.../iTunes.11.4.0.exe  (2db8ec6ed90627ec41d1a8ea1ac55fac)

0 / 68
http://i.softplanet.com/.../Virtual-DJ-Home-FREE741.exe  (install_virtualdj_home_v7.4.1-clean.exe)

3 / 68      (Adware)
http://i.softplanet.com/.../Dropbox.2.10.30.exe  (caa047dbeb4bdb05df84fe974be2165d)

0 / 68

1 / 68      (Adware)

1 / 68      (Adware)
http://i.softplanet.com/.../Cheat-Engine.6.3.exe  (56635db7a6bc4cf0d0eef832c7414da4)

1 / 68      (Adware)
http://i.softplanet.com/.../VMware-Player.7.1.0.exe  (a900a875ff56752bd81f74bf758031f0)

1 / 68      (Adware)

1 / 68      (Adware)
http://i.softplanet.com/.../Opera.24.0.1558.61.exe  (84d7b2097f2bad27f46281777bb21b57)

1 / 68      (Adware)
http://i.softplanet.com/.../Cheat-Engine.6.4.exe  (c0b1c2aa962e8ae69c229c0b690b32c2)

6 / 68      (PUP)

7 / 68      (Adware)
http://i.softplanet.com/.../Skype.7.4.0.102.exe  (f19138054326ff3c299ac4c10dcf6f1c)

 
Latest 30 of 254 download URLs

The following 354 files have been seen to comunicate with i.softplanet.com in live environments.

 
Latest 20 of 760 files

URL:
http://i.softplanet.com/

Network:
Amazon Cloudfront

Web server:
AmazonS3