softy.line55.net

NAMECHEAP.COM

Domain Information

The domain softy.line55.net registered by NAMECHEAP.COM was initially registered in February of 2009 through ENOM, INC.. Currently this domain has been known to host various forms of malware. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
Arizona, United States (US)

Create date:
Saturday, February 21, 2009

Expires date:
Thursday, February 21, 2019

Updated date:
Wednesday, December 16, 2015

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Root domain:

Google Safe Browsing:
unwanted

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP
88.89%

ESET NOD32
Win32/Sality.NBA virus
22.22%

VIPRE Antivirus
Threat.4721115
11.11%

Microsoft Security Essentials
Threat.Undefined
11.11%

F-Prot
W32/Sality.gen2
11.11%

Dr.Web
Win32.Sector.30
11.11%

Emsisoft Anti-Malware
Win32.Sality
11.11%

avast!
Win32:Sality
11.11%

Kaspersky
Virus.Win32.Sality
11.11%

McAfee
Trojan.Artemis!BF71E0F1521E
11.11%

AVG
Win32/Sality
11.11%

The domain softy.line55.net has been seen to resolve to the following 2 IP addresses.

March 31, 2016

March 31, 2016

File downloads found at URLs served by softy.line55.net.

1 / 68      (Malware)
https://softy.line55.net/.../win32.exe  (3e7c67cbb9a9f6e860b46ed36e6fbfa7)

1 / 68      (Malware)
https://softy.line55.net/.../under.exe  (a0fdd29c3b3ca4269e4051742617eb3e)

1 / 68      (Malware)
https://softy.line55.net/.../start.exe  (4246252579521704831342d6d0cbfd86)

1 / 68      (Malware)
https://softy.line55.net/.../Opera.exe  (054f2db6da9a3afd265ef3439b40dde8)

1 / 68      (Malware)
https://softy.line55.net/.../app-chrome.exe  (cb1263e39b136d49555706b717385df3)

1 / 68      (Malware)
https://softy.line55.net/.../short.exe  (fc98727b7641d3726895dcf502646b5f)

11 / 68    (Malware)
http://softy.line55.net/FLV-HD.exe  (4c670c87509fd0ec7633fbf1a2fdf7f7)

1 / 68      (Malware)
https://softy.line55.net/.../Install.exe  (39150956f012947f65910146f2354357)

1 / 68      (Malware)
https://softy.line55.net/.../Mozilla Firefox.exe  (8a2a058658ab8e5ff397ed6895cf2fc8)

URL:
http://softy.line55.net/

SSL certificate subject:
CN=sni67905.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx