microsoft-visual-cpp-express.soft32.com

I.T.N.T. SRL

Domain Information

The domain microsoft-visual-cpp-express.soft32.com registered by I.T.N.T. SRL was initially registered in September of 2003 through ENOM, INC.. The domain hosts various software downloads. The hosted servers are located in Dulles, Virginia within the United States. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).

This Soft32 domain (part of the Soft32.com site) displays information for the software program microsoft visual cpp express as well as provides 'free' downloads managed through the Soft32's Download Manager (which might include potentially unwanted offers such as the AVG Toolbar).
Registrar:
ENOM, INC.

Server location:
Virginia, United States (US)

Create date:
Monday, September 29, 2003

Expires date:
Sunday, September 29, 2024

Updated date:
Monday, October 6, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc., US

Root domain:

Scanner detections:
Detections  (86% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Downloader.Bundler.Soft32.Installer (M), Threat.Win.Reputation.IMP, PUP.Downloader.Bundler.Soft32 (M)
83.33%

McAfee
W32/Gnamer, Virus.W32/Sality.gen.z
16.67%

avast!
Win32:Agent-AODJ [Trj], Win32:SaliCode
16.67%

Kaspersky
Virus.Win32.Renamer, Virus.Win32.Sality
16.67%

Emsisoft Anti-Malware
Worm.Generic.377772, Win32.Sality
16.67%

Dr.Web
Trojan.Inject1.28681, Win32.Sector.30
16.67%

Sophos
Troj/Zbot-IQS, Virus 'Mal/Sality-D'
16.67%

F-Prot
W32/Renamer.A.gen, W32/Sality.gen2
16.67%

Microsoft Security Essentials
Virus:Win32/Grenam.A, Threat.Undefined
16.67%

AVG
Worm/Delf, Win32/Sality
16.67%

Bkav FE
W32.FakeExeYHPtv
8.33%

Total Defense
Win32/Grenam.A
8.33%

MicroWorld eScan
Worm.Generic.377772
8.33%

nProtect
Trojan/W32.Agent.534016.BS
8.33%

Quick Heal
W32.Grenam.A
8.33%

The domain microsoft-visual-cpp-express.soft32.com has been seen to resolve to the following 13 IP addresses.

server-54-192-192-199.iad53.r.cloudfront.net
August 30, 2016

server-54-192-192-179.iad53.r.cloudfront.net
August 30, 2016

server-54-192-192-123.iad53.r.cloudfront.net
August 30, 2016

server-54-192-192-97.iad53.r.cloudfront.net
August 30, 2016

server-54-192-192-87.iad53.r.cloudfront.net
August 30, 2016

server-54-192-192-53.iad53.r.cloudfront.net
August 30, 2016

server-54-192-192-24.iad53.r.cloudfront.net
August 30, 2016

server-54-192-192-205.iad53.r.cloudfront.net
August 30, 2016

February 6, 2016

July 1, 2015

July 1, 2015

a23-67-242-57.deploy.static.akamaitechnologies.com
April 4, 2014

a23-67-242-48.deploy.static.akamaitechnologies.com
April 4, 2014

File downloads found at URLs served by microsoft-visual-cpp-express.soft32.com.

1 / 68      (Adware)
http://microsoft-visual-cpp-express.soft32.com/get/file/id/.../  (microsoft visual c 2010 express setup.exe)

1 / 68      (Malware)

1 / 68      (Adware)
http://microsoft-visual-cpp-express.soft32.com/get/file/id/.../  (microsoft visual c 2010 express setup.exe)

1 / 68      (Adware)
http://microsoft-visual-cpp-express.soft32.com/get/file/id/.../  (microsoft visual c 2010 express setup.exe)

38 / 68    (Malware)

1 / 68      (Adware)
http://microsoft-visual-cpp-express.soft32.com/get/file/id/.../  (microsoft visual c 2010 express setup.exe)

1 / 68      (Adware)
http://microsoft-visual-cpp-express.soft32.com/get/file/id/.../  (microsoft visual c 2010 express setup.exe)

1 / 68      (Adware)
http://microsoft-visual-cpp-express.soft32.com/get/file/id/.../  (microsoft visual c 2010 express setup.exe)

1 / 68      (Adware)
http://microsoft-visual-cpp-express.soft32.com/get/file/id/.../  (microsoft visual c 2010 express setup.exe)

The following 88 files have been seen to comunicate with microsoft-visual-cpp-express.soft32.com in live environments.

 
Latest 20 of 104 files

URL:
http://microsoft-visual-cpp-express.soft32.com/

Google Analytics:
UA-110868

Title:
“Download Microsoft Visual C++ 2010 Express 10”

Description:
“Microsoft Visual C++ 2010 Express free download. Get the latest version now. Visual C++ 2010 Express is part of the Visual Studio 2010 Express family.”

Network:
Amazon Cloudfront

Web server:
nginx

Facebook:
Likes:  18
Shares:  53
Comments:  50

Statistics are for the previous month.