windows-xp-service-pack-3.soft32.com

I.T.N.T. SRL

Domain Information

The domain windows-xp-service-pack-3.soft32.com registered by I.T.N.T. SRL was initially registered in September of 2003 through ENOM, INC.. The domain hosts various software downloads. The hosted servers are located in Seattle, Washington within the United States which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Cloudfront CDN service which utilizes a number of proxy IP Addresses (see below).

This Soft32 domain (part of the Soft32.com site) displays information for the software program windows xp service pack 3 as well as provides 'free' downloads managed through the Soft32's Download Manager (which might include potentially unwanted offers such as the AVG Toolbar).
Registrar:
ENOM, INC.

Server location:
Washington, United States (US)

Create date:
Monday, September 29, 2003

Expires date:
Sunday, September 29, 2024

Updated date:
Friday, December 11, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc., US

Root domain:

Scanner detections:
Detections  (93% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ZuluSoftSRL.FF, PUP.Downloader.Bundler.Soft32.Installer, PUP.Downloader.Bundler.Soft32.Installer (M), PUP.Downloader.Bundler.Soft32 (M)
100.00%

Malwarebytes
PUP.Optional.Soft32.A, PUP.Optional.AdBundle, PUP.Optional.Zulu
46.15%

NANO AntiVirus
Riskware.Nsis.Downloader.cvxhzw, Riskware.Win32.Downloader.cvxhzw
46.15%

Dr.Web
Adware.Downware.2152, Worm.Siggen.9820, Adware.Downware.9012
46.15%

VIPRE Antivirus
Soft32Downloader, Threat.4783370
46.15%

ESET NOD32
MSIL/Soft32Downloader.A potentially unwanted application, Win32/Soft32Downloader.D potentially unwanted application, MSIL/Soft32Downloader.C potentially unwanted application
30.77%

Avira AntiVirus
APPL/Downloader.Gen, TR/Crypt.ULPM.Gen
30.77%

Agnitum Outpost
PUA.Soft32Downloader, PUA.Downware
30.77%

ESET NOD32
MSIL/Soft32Downloader (variant)
15.38%

Clam AntiVirus
Win.Adware.Toggle-4
15.38%

McAfee
Downloader-FMA, Artemis!E6A73348F0B6
15.38%

McAfee Web Gateway
BehavesLike.Win32.Downloader.dc, BehavesLike.Win32.Downloader.hc
15.38%

avast!
Malware-gen, Dropper-gen [Drp]
15.38%

K7 AntiVirus
Unwanted-Program
7.69%

F-Prot
W32/Soft32Download.A.gen
7.69%

The domain windows-xp-service-pack-3.soft32.com has been seen to resolve to the following 20 IP addresses.

server-52-84-127-236.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-224.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-205.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-182.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-96.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-87.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-85.iad16.r.cloudfront.net
September 16, 2016

server-52-84-127-68.iad16.r.cloudfront.net
September 16, 2016

January 6, 2016

December 23, 2015

December 23, 2015

September 4, 2014

September 2, 2014

September 2, 2014

August 19, 2014

August 19, 2014

a23-67-242-57.deploy.static.akamaitechnologies.com
April 16, 2014

a23-67-242-48.deploy.static.akamaitechnologies.com
April 16, 2014

November 19, 2013

November 19, 2013

File downloads found at URLs served by windows-xp-service-pack-3.soft32.com.

The following 101 files have been seen to comunicate with windows-xp-service-pack-3.soft32.com in live environments.

 
Latest 20 of 101 files

URL:
http://windows-xp-service-pack-3.soft32.com/

Google Analytics:
UA-110868

Title:
“Download Windows XP Service Pack 3 Build 5512 FINAL”

Description:
“Windows XP Service Pack 3 free download. Get the latest version now. Windows XP Service Pack 3 Build 5512 FINAL”

Network:
Amazon Cloudfront

Web server:
nginx

Facebook:
Likes:  70
Shares:  32
Comments:  2

Statistics are for the previous month.