software.trustydownloads.com

Air Software

Domain Information

The domain software.trustydownloads.com registered by China Capital Investment Limited was initially registered in January of 2013 through GODADDY.COM, LLC. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Belfast, Northern Ireland within United Kingdom which resides on the RIPE Network Coordination Centre network. The domain is associated with the publisher Air Software who is located in Victoria, British Columbia in Canada.
Registrar:
GODADDY.COM, LLC

Server location:
Northern Ireland, United Kingdom (GB)

Create date:
Wednesday, January 30, 2013

Expires date:
Monday, January 30, 2017

Updated date:
Monday, March 14, 2016

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.DownloadManager.F, DownloadManager.AirSoftware.P, PUP.Air Software.DownloadManager.Bundler (M), PUP.Air Software.AirSoftware.Bundler (M), PUP.Air Software.Download.Bundler (M), PUP.Air Software.AirSoftw.Bundler (M), PUP.Air Software (M)
96.77%

K7 Gateway Antivirus
Unwanted-Program
22.58%

K7 AntiVirus
Unwanted-Program , Adware
22.58%

avast!
Win32:Malware-gen, PUP-gen [PUP], Win32:Installer-L [PUP], Win32:Adware-CAH [PUP]
22.58%

Dr.Web
Trojan.SMSSend.4902, Trojan.SMSSend.4317, Adware.Downware.2035, Trojan.SMSSend.4543
22.58%

VIPRE Antivirus
Iminent, Threat.4782985, AirInstaller
22.58%

Avira AntiVirus
ADWARE/Adware.Gen, Adware/AirInst.1174, Adware/AgentCV.A.3144, ADWARE/Adware.Gen7
22.58%

Rising Antivirus
PE:PUF.Airinstall!1.9C4C
22.58%

AVG
BundleApp_r.D, Adware Generic_r.JA, Adware BundleApp_r.D
22.58%

F-Prot
W32/AirInstall.A.gen, W32/A-8c0ea402
19.35%

NANO AntiVirus
Riskware.Win32.AirAdInstaller.cxhlvu, Riskware.Win32.AirAdInstaller.daxzhz, Riskware.Win32.AirAdInstaller.dmnhwl, Riskware.Win32.Downware.cwfgel
19.35%

Comodo Security
Application.Win32.AirAdInstaller.B, Application.Win32.AirAdInstaller.A
19.35%

Sophos
AirInstaller, PUA 'AirInstaller'
19.35%

Antiy Labs AVL
Spyware[AdWare:not-a-virus]/Win32.AirAdInstaller, Trojan[:HEUR]/Win32.AGeneric
19.35%

G Data
Win32.Adware.Airadinstaller, Gen:Variant.Application.Bundler.AirInstaller
19.35%

The domain software.trustydownloads.com has been seen to resolve to the following 7 IP addresses.

192.230.92.93.ip.incapdns.net
August 6, 2016

199.83.132.93.ip.incapdns.net
June 24, 2016

192.230.66.93.ip.incapdns.net
June 21, 2016

April 9, 2016

ip-50-63-202-44.ip.secureserver.net
February 10, 2016

unallocated.barefruit.co.uk
August 1, 2014

April 13, 2014

File downloads found at URLs served by software.trustydownloads.com.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://software.trustydownloads.com/.../skype.exe  (81007f311f21af514595e693b8f3dcc1)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://software.trustydownloads.com/.../realplayer.exe  (3ce839f4569d7ec691d7db8283ddf86d)

1 / 68      (Adware)

11 / 68    (Adware)

The following 240 files have been seen to comunicate with software.trustydownloads.com in live environments.

 
Latest 20 of 240 files

URL:
http://software.trustydownloads.com/

Web server:
nginx/1.8.1