softwarerus.ru

Private Person  (Proxy Registrant)

Domain Information

The domain softwarerus.ru is registered by proxy through NAUNET-RU and was originally registered in October of 2011. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Road Town, British Virgin Islands within VG which resides on the RIPE Network Coordination Centre network.
Registrar:
NAUNET-RU

Server location:
British Virgin Islands, VG (VG)

Create date:
Thursday, October 20, 2011

Expires date:
Thursday, October 20, 2016

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.MediaGet.Banner.Installer (M), PUP.MediaGet.Inbox.Installer (M)
100.00%

Bkav FE
W32.HfsAdware
50.00%

Malwarebytes
PUP.Optional.MediaGet
50.00%

ESET NOD32
Win32/MediaGet.AE potentially unwanted (variant)
50.00%

Kaspersky
not-a-virus:HEUR:Downloader.Win32.MediaGet
50.00%

Comodo Security
Application.Win32.MediaGet.G
50.00%

Dr.Web
Program.MediaGet.133
50.00%

Sophos
MediaGet (PUA)
50.00%

G Data
Win32.Adware.MediaGet
50.00%

IKARUS anti.virus
PUA.MediaGet
50.00%

AVG
Banne
50.00%

Baidu Antivirus
Adware.Win32.MediaGet
50.00%

Qihoo 360 Security
Win32/Virus.e7d
50.00%

The domain softwarerus.ru has been seen to resolve to the following IP address.

dev.ucoz.net
July 4, 2016

File downloads found at URLs served by softwarerus.ru.

13 / 68    (PUP)
http://softwarerus.ru/.../0-0-1-222-20  (mediaget_id2772891ids2s.exe)

1 / 68      (PUP)
http://softwarerus.ru/.../0-0-1-222-20  (outlast-full-turkce-indir_id2959289ids2s.exe)

The following file have been seen to comunicate with softwarerus.ru in live environments.

URL:
http://softwarerus.ru/

Title:
“Программы для компьютера, скачать программу с Softwarerus”

Description:
“На нашем сайте Softwarerus.ru имеется огромное количество программного обеспечения, которое вы можете скачать по прямым ссылкам. Здесь собраны программы разных категорий и предназначения, для работы и отдыха.”

Web server:
nginx/1.8.0