portable-firefox.soft32.com

I.T.N.T. SRL

Domain Information

The domain portable-firefox.soft32.com registered by I.T.N.T. SRL was initially registered in September of 2003 through ENOM, INC.. The domain hosts various software downloads. The hosted servers are located in Seattle, Washington within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).

This Soft32 domain (part of the Soft32.com site) displays information for the software program portable firefox as well as provides 'free' downloads managed through the Soft32's Download Manager (which might include potentially unwanted offers such as the AVG Toolbar).
Registrar:
ENOM, INC.

Server location:
Washington, United States (US)

Create date:
Monday, September 29, 2003

Expires date:
Sunday, September 29, 2024

Updated date:
Friday, December 11, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc., US

Root domain:

Scanner detections:
Detections  (86% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Downloader.Bundler.Soft32.Installer, PUP.Downloader.Bundler.Soft32.Installer (M), PUP.Downloader.Bundler.Soft32 (M)
100.00%

nProtect
Adware/W32.Agent.1116952
16.67%

Malwarebytes
PUP.Soft32Downloader
16.67%

Agnitum Outpost
PUA.Soft32Downloader
16.67%

F-Prot
W32/Soft32Download.C.gen
16.67%

SUPERAntiSpyware
PUP.Downloader/Variant
16.67%

Comodo Security
Application.Win32.Soft32Downloader.S
16.67%

Dr.Web
Adware.Downware.971
16.67%

VIPRE Antivirus
Soft32Downloader
16.67%

Avira AntiVirus
APPL/Downloader.Gen
16.67%

Vba32 AntiVirus
AdWare.DownloadWare.mz
16.67%

ESET NOD32
Win32/Soft32Downloader.D potentially unwanted application
16.67%

Rising Antivirus
PE:PUF.Soft32Downloader!1.9C52
16.67%

Fortinet FortiGate
Adware/Softdownmgr
16.67%

Trend Micro House Call
TROJ_GEN.F47V1124
16.67%

The domain portable-firefox.soft32.com has been seen to resolve to the following 29 IP addresses.

server-52-84-127-236.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-224.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-205.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-182.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-96.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-87.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-85.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-68.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-157.iad16.r.cloudfront.net
September 1, 2016

server-52-84-127-146.iad16.r.cloudfront.net
September 1, 2016

server-52-84-127-95.iad16.r.cloudfront.net
September 1, 2016

server-52-84-127-80.iad16.r.cloudfront.net
September 1, 2016

server-52-84-127-49.iad16.r.cloudfront.net
September 1, 2016

server-52-84-127-238.iad16.r.cloudfront.net
September 1, 2016

server-52-84-127-171.iad16.r.cloudfront.net
September 1, 2016

server-52-84-127-161.iad16.r.cloudfront.net
September 1, 2016

server-52-84-127-193.iad16.r.cloudfront.net
August 13, 2016

server-52-84-127-150.iad16.r.cloudfront.net
August 13, 2016

server-52-84-127-112.iad16.r.cloudfront.net
August 13, 2016

server-52-84-127-100.iad16.r.cloudfront.net
August 13, 2016

server-52-84-127-72.iad16.r.cloudfront.net
August 13, 2016

server-52-84-127-248.iad16.r.cloudfront.net
August 13, 2016

server-52-84-127-235.iad16.r.cloudfront.net
August 13, 2016

server-52-84-127-214.iad16.r.cloudfront.net
August 13, 2016

June 22, 2016

March 31, 2016

March 31, 2016

February 10, 2015

February 10, 2015

File downloads found at URLs served by portable-firefox.soft32.com.

The following 8 files have been seen to comunicate with portable-firefox.soft32.com in live environments.

URL:
http://portable-firefox.soft32.com/

Google Analytics:
UA-110868

Title:
“Download Mozilla Firefox Portable 40.0.2”

Description:
“Mozilla Firefox Portable free download. Get the latest version now. Portable Firefox is a fully functional package of Firefox optimized for use on a USB key drive.”

Network:
Amazon Cloudfront

Web server:
nginx

Facebook:
Likes:  7
Shares:  1

Statistics are for the previous month.