www.downxsoft.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain www.downxsoft.com is registered by proxy through GODADDY.COM, LLC and was originally registered in April of 2012. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dusseldorf, Nordrhein-Westfalen within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
GODADDY.COM, LLC

Server location:
Nordrhein-Westfalen, Germany (DE)

Create date:
Tuesday, April 17, 2012

Expires date:
Monday, April 17, 2017

Updated date:
Tuesday, May 5, 2015

ASN:
AS25074 INETBONE-AS MESH GmbH

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.BetterInstaller.Somoto.F, PUP.BetterInstaller.Somoto.AA, PUP.BetterInstaller.Somoto.W, PUP.BetterInstaller.Somoto.DD, PUP.Installer.Somoto.CC, PUP.Somoto.Bundler (M), Adware.Somoto.Installer.Meta (M), PUP.Somoto (M)
100.00%

Malwarebytes
PUP.Optional.Somoto, PUP.Optional.Somoto.A
68.18%

ESET NOD32
Win32/Somoto
68.18%

avast!
Win32:Somoto-F [PUP], Win32:Somoto-J [PUP], Win32:Somoto-O [PUP]
63.64%

Clam AntiVirus
Adware.Somoto-1, Trojan.Agent-267630
63.64%

Dr.Web
Adware.Somoto.17, Adware.Downware.1184, Trojan.MulDrop4.11744
63.64%

VIPRE Antivirus
BetterInstaller, Trojan.Win32.Generic
63.64%

Avira AntiVirus
APPL/Somoto.gei, APPL/Somoto.fya, Adware/BetterInstall.BI, APPL/Somoto.Gen2
63.64%

Sophos
Somoto BetterInstaller
63.64%

Comodo Security
Application.Win32.Somoto.A, Application.Win32.Somoto.DTL
50.00%

G Data
Win32.Application.Somoto, NSIS.Application.Somoto, Application.Bundler.Somoto
50.00%

AVG
AdInstaller.Somoto, Downloader
50.00%

Panda Antivirus
PUP/MultiToolbar.A
45.45%

NANO AntiVirus
Trojan.Win32.Agent.cruvhh, Trojan.Nsis.Mazel.cwhyud
31.82%

Baidu Antivirus
Adware.Win32.Somoto
31.82%

The domain www.downxsoft.com has been seen to resolve to the following IP address.

January 18, 2014

File downloads found at URLs served by www.downxsoft.com.

1 / 68      (Adware)

1 / 68      (Adware)

9 / 68      (Adware)

9 / 68      (Adware)

1 / 68      (Adware)
http://www.downxsoft.com/.../FLVPlayerSetup-Ne3ESzZBe.exe  (be53cb1dd9912239208fd2cdbbf50f79)

22 / 68    (Adware)

9 / 68      (Adware)

20 / 68    (Adware)

1 / 68      (PUP)

19 / 68    (Adware)

1 / 68      (Adware)
http://www.downxsoft.com/.../FLVPlayerSetup-N6WT1XzIn.exe  (clickheretodownloadsetup-cj7owl2t.exe)

1 / 68      (Adware)
http://www.downxsoft.com/.../FreeZipSetup-N4FvdfVXF.exe  (c80d7ac070885626777615506e74071b)

9 / 68      (Adware)

9 / 68      (Adware)

22 / 68    (Adware)

22 / 68    (Adware)

9 / 68      (Adware)

20 / 68    (Adware)

23 / 68    (Adware)
http://www.downxsoft.com/.../FreeZipSetup-N6w6lNGXp.exe  (62d5806bedef5d04a9e1b7ce02844c1a)

22 / 68    (Adware)

9 / 68      (Adware)

16 / 68    (Adware)
http://www.downxsoft.com/.../FreeZipSetup-N3rpf3Uf2.exe  (0223d5b52de65da813b48611a769bf9a)

16 / 68    (Adware)
http://www.downxsoft.com/.../FreeZipSetup-NbyNPoLKQ.exe  (2ea6b57f8c1a390e2221e6a5f1ba7759)

15 / 68    (Adware)

16 / 68    (Adware)

15 / 68    (Adware)
http://www.downxsoft.com/.../FLVPlayerSetup-Nfq50ETdC.exe  (393a85a40b0eef1fb37c45c796379747)

22 / 68    (Adware)

1 / 68      (Adware)

11 / 68    (Adware)

10 / 68    (Adware)

 
Latest 30 of 76 download URLs

URL:
http://www.downxsoft.com/

Web server:
nginx