softwareforfree.net

Only contact by email, all postal mail will be rejected  (Proxy Registrant)

Domain Information

The domain softwareforfree.net is registered by proxy through SOLUCIONES CORPORATIVAS IP,SLU and was originally registered in July of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Montreal, Quebec within Canada which resides on the OVH Hosting, Inc. network.
Registrar:
SOLUCIONES CORPORATIVAS IP,SLU

Server location:
Quebec, Canada (CA)

Create date:
Monday, July 28, 2014

Expires date:
Tuesday, July 28, 2015

Updated date:
Wednesday, September 3, 2014

ASN:
AS16276 OVH OVH SAS

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.GeryonAdsSL.P, PUP.GeryonAdsSL.BB, PUP.Installer.GeryonAdsSL.P, PUP.GeryonAds.Installer (M), PUP.installCore.GeryonAds (M), PUP.Solimba.Bechirosl (M)
95.83%

Baidu Antivirus
Adware.Win32.InstallCore
75.00%

ESET NOD32
Win32/InstallCore.QL (variant), Win32/InstallCore.PQ (variant), Win32/InstallCore.PL (variant), Win32/InstallCore.QF (variant)
66.67%

VIPRE Antivirus
Trojan.Win32.Generic, InstallCore, Threat.4786018
41.67%

McAfee
Artemis!F55B7494E455, Artemis!0C5955E2E09E, Artemis!F4A9D2711A8B, Artemis!E7AA7D55E757, Artemis!41515E28707D, Artemis!0418C1B1BCB5, Artemis!79B40986441A, Artemis!3DF34A0BC90A
37.50%

Avira AntiVirus
ADWARE/InstallCore.Gen7, ADWARE/InstallCore.Gen9, Adware/InstallCore.A.231, Adware/InstallCore.801096, Adware/InstallCore.A.365
37.50%

AVG
Generic
33.33%

Fortinet FortiGate
Riskware/InstallCore
29.17%

Trend Micro House Call
Suspicious_GEN.F47V0907, TROJ_GEN.R02SC0OJS14, Suspicious_GEN.F47V1116, Suspicious_GEN.F47V1112, Suspicious_GEN.F47V1206, Suspicious_GEN.F47V1110
29.17%

Dr.Web
Trojan.MulDrop5.38104, Trojan.Packed.28933, Trojan.InstallCore.1903
25.00%

Sophos
Generic PUA CJ, Generic PUA GD, Generic PUA PF, Generic PUA HJ
16.67%

K7 AntiVirus
Trojan , Unwanted-Program
16.67%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
12.50%

ESET NOD32
Win32/InstallCore.TL potentially unwanted application, Win32/InstallCore.AFI.gen potentially unwanted application, Win32/InstallCore.AFV potentially unwanted application
12.50%

herdProtect (fuzzy)
a variant of 400026c157117c9e02a0d7b8a650c8f6a92ba30d
4.17%

The domain softwareforfree.net has been seen to resolve to the following IP address.

ks4010563.ip-192-99-10.net
September 11, 2014

File downloads found at URLs served by softwareforfree.net.

2 / 68      (PUP)

1 / 68      (Adware)
http://softwareforfree.net/.../skype2014.php  (icreinstall_skype_installer.exe)

4 / 68      (PUP)

7 / 68      (Adware)

0 / 68

0 / 68

1 / 68      (Adware)

1 / 68      (Adware)

7 / 68      (Adware)

2 / 68      (Adware)

9 / 68      (Adware)

12 / 68    (Adware)

1 / 68      (Adware)

8 / 68      (Adware)

6 / 68      (Adware)

10 / 68    (Adware)

3 / 68      (Adware)

13 / 68    (Adware)

8 / 68      (Adware)

7 / 68      (Adware)

4 / 68      (Adware)
http://softwareforfree.net/.../skype.php  (icreinstall_skype_installer.exe)

6 / 68      (Adware)
http://softwareforfree.net/.../skype.php  (icreinstall_skype_installer.exe)

8 / 68      (Adware)

8 / 68      (Adware)

3 / 68      (Adware)
http://softwareforfree.net/.../skype.php  (icreinstall_skype_installer.exe)

3 / 68      (Adware)

6 / 68      (Adware)

URL:
http://softwareforfree.net/

Title:
“Redirect to Win-Software.net's Minecraft site”

Web server:
Apache