i.softplanet.com

Secure Download Ltd

Domain Information

The domain i.softplanet.com registered by Secure Download Ltd was initially registered in August of 1996 through WILD WEST DOMAINS, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Seattle, Washington within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Remove Malware from i.softplanet.com - Powered by Reason Core Security
Registrar:
WILD WEST DOMAINS, LLC

Server location:
Washington, United States (US)

Create date:
Thursday, August 29, 1996

Expires date:
Sunday, August 28, 2022

Updated date:
Friday, May 10, 2013

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (64% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.KuzyakovArturVyacheslavovichIP.M, PUP.SecureDownload.M, Threat.AVSoftware EOOD.SecureDownload, PUP.AVSoftware EOOD.SecureDownload (M)
86.11%

Dr.Web
Trojan.Click3.11442, Program.Unwanted.291, Adware.Downware.11222
19.44%

avast!
Win32:Malware-gen, Win32:Rootkit-gen [Rtk]
16.67%

McAfee Web Gateway
BehavesLike.Win32.GameVance.jc, Artemis, BehavesLike.Win32.Downloader.jc
13.89%

AVG
Downloader
13.89%

McAfee
Virus.W32/Sality.gen.z, Artemis!C02472CB052C, Artemis!190D8EC7E130, Artemis!43179E8138FD
11.11%

Avira AntiVirus
W32/Mabezat, PUA/Downware.707584.2
5.56%

ESET NOD32
Win32/OpenCandy, Win32/OpenCandy.C potentially unsafe (variant)
5.56%

G Data
Win32.Adware.iObit, Win32.Sality
5.56%

Trend Micro House Call
Suspicious_GEN.F47V0309, Suspicious_GEN.F47V0810
5.56%

Bkav FE
W32.Clod726.Trojan, W32.Clod544.Trojan
5.56%

Emsisoft Anti-Malware
Gen:Variant.Graftor.66610
2.78%

ESET NOD32
Detection.Undefined
2.78%

VIPRE Antivirus
Threat.4721115
2.78%

Microsoft Security Essentials
Threat.Undefined
2.78%

The domain i.softplanet.com has been seen to resolve to the following 330 IP addresses.

server-54-240-160-234.iad12.r.cloudfront.net
February 9, 2016

server-54-240-160-165.iad12.r.cloudfront.net
February 9, 2016

server-54-192-195-17.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-251.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-231.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-217.iad53.r.cloudfront.net
February 8, 2016

server-54-192-195-53.iad53.r.cloudfront.net
February 8, 2016

server-54-240-160-211.iad12.r.cloudfront.net
January 31, 2016

server-54-240-160-208.iad12.r.cloudfront.net
January 31, 2016

server-54-240-160-129.iad12.r.cloudfront.net
January 31, 2016

server-54-240-160-85.iad12.r.cloudfront.net
January 31, 2016

server-54-240-160-30.iad12.r.cloudfront.net
January 31, 2016

server-54-192-195-141.iad53.r.cloudfront.net
January 31, 2016

server-54-192-195-105.iad53.r.cloudfront.net
January 31, 2016

server-54-192-195-96.iad53.r.cloudfront.net
January 28, 2016

server-54-192-195-82.iad53.r.cloudfront.net
January 28, 2016

server-54-192-195-68.iad53.r.cloudfront.net
January 28, 2016

server-54-192-195-22.iad53.r.cloudfront.net
January 28, 2016

server-54-192-195-11.iad53.r.cloudfront.net
January 28, 2016

server-54-192-195-203.iad53.r.cloudfront.net
January 28, 2016

server-54-192-195-119.iad53.r.cloudfront.net
January 28, 2016

server-54-192-195-118.iad53.r.cloudfront.net
January 28, 2016

server-54-240-160-10.iad12.r.cloudfront.net
January 27, 2016

server-54-240-160-254.iad12.r.cloudfront.net
January 27, 2016

server-54-240-160-241.iad12.r.cloudfront.net
January 27, 2016

server-54-240-160-239.iad12.r.cloudfront.net
January 27, 2016

server-54-240-160-110.iad12.r.cloudfront.net
January 27, 2016

server-54-240-160-100.iad12.r.cloudfront.net
January 27, 2016

server-54-240-160-25.iad12.r.cloudfront.net
January 27, 2016

server-54-240-160-20.iad12.r.cloudfront.net
January 27, 2016

 
Showing 30 of 330 IP Addresses

File downloads found at URLs served by i.softplanet.com.

1 / 68      (Adware)
http://i.softplanet.com/.../Spotify.1.0.2.6.exe  (a186234e69364dfae531f9319fe60e0b)

1 / 68      (Adware)

0 / 68

7 / 68      (Adware)
http://i.softplanet.com/.../WinRAR.5.21.0.exe  (190d8ec7e130d14ce0261df0117fcf56)

5 / 68      (inconclusive)

0 / 68

11 / 68    (false positives)

1 / 68      (Adware)
http://i.softplanet.com/.../WinSCP.5.7.2.exe  (b058197c67718e89843b3a11429e1198)

6 / 68      (Adware)

0 / 68
http://i.softplanet.com/.../Dropbox21030.exe  (dropbox_2.10.30_cb-dl-manager.exe)

1 / 68      (Adware)
http://i.softplanet.com/.../Fotosizer.2.09.0.548.exe  (70d8feca2dcf255e8eabb5e10ac6e903)

0 / 68
http://i.softplanet.com/.../Fotosizer2090548.exe  (fotosizer 2.09.0.548 free.exe)

1 / 68

0 / 68
http://i.softplanet.com/.../221-1.exe  (vlc-2.2.1-win32.exe)

8 / 68      (Adware)
http://i.softplanet.com/.../VLC-Media-Player.2.2.1.exe  (43179e8138fdf4787d94ef9f4eeb8c00)

4 / 68      (Adware)
http://i.softplanet.com/.../Dropbox.2.10.30.exe  (4b115761635675d8ab6520f6d343bf3a)

1 / 68      (Adware)

1 / 68      (Adware)
http://i.softplanet.com/.../Hamachi.2.2.0.236.exe  (e12bde6c8f620d9579342f297a60f505)

1 / 68      (Adware)
http://i.softplanet.com/.../DriverEasy.4.9.1.0.exe  (92ceb980fa83ecce0cfa5e492ee4612f)

1 / 68      (Adware)
http://i.softplanet.com/.../Magic-Camera.8.8.3.exe  (4015e98d9dcd1899e0de6801983f93af)

1 / 68      (Adware)

1 / 68      (Adware)
http://i.softplanet.com/.../AIMP.3.60.148327.02.2015.exe  (042de5079b13e96bd393c31c5ddb1fd1)

1 / 68      (Adware)

1 / 68      (Adware)

0 / 68

 
Latest 30 of 103 download URLs

The following 57 files have been seen to comunicate with i.softplanet.com in live environments.

 
Latest 20 of 64 files

URL:
http://i.softplanet.com/

Network:
Amazon Cloudfront

Web server:
AmazonS3

Remove Malware from i.softplanet.com - Powered by Reason Core Security