viber.soft32.com

I.T.N.T. SRL

Domain Information

The domain viber.soft32.com registered by I.T.N.T. SRL was initially registered in September of 2003 through ENOM, INC.. The domain hosts various software downloads. The hosted servers are located in Seattle, Washington within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).
Registrar:
ENOM, INC.

Server location:
Washington, United States (US)

Create date:
Monday, September 29, 2003

Expires date:
Sunday, September 29, 2024

Updated date:
Monday, October 06, 2014

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc., US

Root domain:

Scanner detections:
Detections  (69% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ZuluSoftSRL.L, PUP.Installer.RICHMEDIASYSTEMS, PUP.Downloader.Bundler.Soft32.Installer (M), PUP.Downloader.Bundler.Soft32 (M)
90.00%

Malwarebytes
PUP.Optional.Soft32.A, PUP.Optional.OpenCandy
30.00%

VIPRE Antivirus
Soft32Downloader, Sevas-S Installer
30.00%

ESET NOD32
MSIL/Soft32Downloader (variant), Win32/OpenCandy.C potentially unsafe (variant)
30.00%

NANO AntiVirus
Riskware.Nsis.Downloader.cvxhzw
20.00%

Dr.Web
Adware.Downware.2152
20.00%

Clam AntiVirus
Win.Adware.Searchsuite-3, Win.Trojan.Agent-855157
20.00%

K7 Gateway Antivirus
Trojan
10.00%

K7 AntiVirus
Trojan
10.00%

Trend Micro House Call
Suspicious_GEN.F47V0414
10.00%

Agnitum Outpost
Riskware.Agent
10.00%

ViRobot
Adware.OpenCandy.425736[h]
10.00%

McAfee Web Gateway
BehavesLike.Win32.Suspicious.gc
10.00%

Sophos
OpenCandy
10.00%

AhnLab V3 Security
PUP/Win32.OpenCandy
10.00%

The domain viber.soft32.com has been seen to resolve to the following 23 IP addresses.

server-52-84-127-68.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-236.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-224.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-205.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-182.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-96.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-87.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-85.iad16.r.cloudfront.net
September 17, 2016

server-52-84-127-95.iad16.r.cloudfront.net
August 31, 2016

server-52-84-127-80.iad16.r.cloudfront.net
August 31, 2016

server-52-84-127-49.iad16.r.cloudfront.net
August 31, 2016

server-52-84-127-238.iad16.r.cloudfront.net
August 31, 2016

server-52-84-127-171.iad16.r.cloudfront.net
August 31, 2016

server-52-84-127-161.iad16.r.cloudfront.net
August 31, 2016

server-52-84-127-157.iad16.r.cloudfront.net
August 31, 2016

server-52-84-127-146.iad16.r.cloudfront.net
August 31, 2016

July 19, 2016

April 14, 2016

August 12, 2015

August 12, 2015

a23-67-242-48.deploy.static.akamaitechnologies.com
April 14, 2014

a23-67-242-80.deploy.static.akamaitechnologies.com
April 14, 2014

a23-67-242-57.deploy.static.akamaitechnologies.com
April 14, 2014

File downloads found at URLs served by viber.soft32.com.

1 / 68      (Adware)

1 / 68      (Adware)

19 / 68    (PUP)

The following 68 files have been seen to comunicate with viber.soft32.com in live environments.

 
Latest 20 of 68 files

URL:
http://viber.soft32.com/

Google Analytics:
UA-110868

Title:
“Download Viber 4.4.0.3606”

Description:
“Viber free download. Get the latest version now. Viber lets you send free messages and make free calls to others.”

Network:
Amazon Cloudfront

Web server:
nginx

Facebook:
Likes:  473
Shares:  52
Comments:  33

Statistics are for the previous month.