www.onestopsoft.com

Elbanhawy Investments

Domain Information

The domain www.onestopsoft.com registered by Elbanhawy Investments was initially registered in November of 2001 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Piscataway, New Jersey within the United States which resides on the Choopa, LLC network.
Registrar:
GODADDY.COM, LLC

Server location:
New Jersey, United States (US)

Create date:
Thursday, November 29, 2001

Expires date:
Tuesday, November 29, 2016

Updated date:
Thursday, October 29, 2015

ASN:
AS20473 AS-CHOOPA - Choopa, LLC

Root domain:

Scanner detections:
Detections  (95% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Bundler.OneStopS.Installer.Meta (M), PUP.Bundler.onestops.Installer.Meta (M), PUP.Bundled.KINGSEDCOSOFTWAREENGINEERINGDEVELOPMENTCO.Installer.Meta (M), PUP.InstallCore.RE11 (M), PUP.Bundler (M)
76.19%

ESET NOD32
Win32/Adware.RK.AP, Win32/Bundled.Toolbar.Ask (variant), Win32/BundleLoader.B potentially unwanted
33.33%

avast!
NSIS:Relevant-I [PUP], Win32:Bundlore-E [PUP], Win32:Oncer
23.81%

Baidu Antivirus
PUA.Win32.BundleLoader, Adware.Win32.Agent, Hacktool.Win32.Toolbar
19.05%

ESET NOD32
Win32/Bundled.Toolbar.Ask potentially unsafe application, Win32/Virut.NBP virus
14.29%

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F], PE:Trojan.Win32.Generic.1733365F!389232223
9.52%

Comodo Security
ApplicUnwnt
4.76%

McAfee
Artemis!F5EFCD43E7AA
4.76%

Trend Micro House Call
Suspicious_GEN.F47V0202
4.76%

NANO AntiVirus
Trojan.Win32.Bundled.dytygn
4.76%

Clam AntiVirus
Win.Adware.Eorezo-528
4.76%

VIPRE Antivirus
Threat.219451
4.76%

Norman
Win32.Runouce.B@mm
4.76%

F-Prot
W32/Thecid.B@mm
4.76%

Emsisoft Anti-Malware
Win32.Runouce.B@mm
4.76%

The domain www.onestopsoft.com has been seen to resolve to the following IP address.

108.61.59.187.choopa.net
April 23, 2014

File downloads found at URLs served by www.onestopsoft.com.

1 / 68      (PUP)
http://www.onestopsoft.com/.../ossax7002.exe  (49579ca40e483b79067e1acf1bbfd9f7)

1 / 68      (PUP)
http://www.onestopsoft.com/.../osshx.exe  (f88fcc20995e4ac5236af8184b899c89)

1 / 68      (PUP)
http://www.onestopsoft.com/.../osshx.exe  (7b7d940f58a5f37137433dd23f08379b)

11 / 68    (Malware)
http://www.onestopsoft.com/.../osshx.exe  (15be76d26dcf33cecc16ff9fc86bb5d8)

1 / 68      (PUP)
http://www.onestopsoft.com/.../osshx.exe  (2a403fffa08013ce6ce93b727c014283)

1 / 68      (PUP)
http://www.onestopsoft.com/.../ossmcp.exe  (59abb5a2d04bc4d1088a41553bb5a171)

1 / 68      (PUP)
http://www.onestopsoft.com/.../osshx.exe  (7ebe710e5f0af83551466f428caf8208)

1 / 68      (PUP)
http://www.onestopsoft.com/.../osshx.exe  (1c4465bb80edbc13a1e0e3e0ec534d48)

1 / 68      (PUP)
http://www.onestopsoft.com/.../osshx.exe  (3c18edf3a7450cb154a0aebe948add57)

0 / 68
http://www.onestopsoft.com/.../ossacb.exe  (b2a7af8b9294bf888772e9de0674d8c1)

3 / 68      (PUP)
http://www.onestopsoft.com/.../ossax7002.exe  (a6c1d7100d1d610e19d11496c39f923d)

1 / 68      (PUP)
http://www.onestopsoft.com/.../osshx.exe  (00ccce6efe73683d35168fc5cf31f364)

3 / 68      (PUP)

1 / 68      (PUP)
http://www.onestopsoft.com/.../osshx.exe  (3040128af5978edea1dab6a299fc2cb8)

4 / 68      (PUP)
http://www.onestopsoft.com/.../ossax7002.exe  (a0ed5df6c8a9c07108680068efe1a49e)

1 / 68      (PUP)
http://www.onestopsoft.com/.../osshx.exe  (fd3e6c4250bac42dc4549a1b29fcef9e)

2 / 68      (PUP)

4 / 68      (PUP)

3 / 68      (PUP)

4 / 68      (PUP)
http://www.onestopsoft.com/.../ossvg.exe  (ab3d3121553c969e3154edf1dd543bcc)

4 / 68      (PUP)
http://www.onestopsoft.com/.../osshx.exe  (f5efcd43e7aaa02ff75d2b9111da75d0)

3 / 68      (PUP)

1 / 68      (PUP)
http://www.onestopsoft.com/.../ossisb3000.exe  (c5bb7ce13cd55119e822f5bdd917f55e)

URL:
http://www.onestopsoft.com/

Title:
“OneStopSoft.com”

Description:
“OneStopSoft, LLC. Is a New England based company. Our management team consists of industry experts bringing experience from such companies as Intel, Lucent General Dynamics, G.E and Microsoft. Their unique and diverse experiences have lead to the...”

Web server:
Apache/2.2.29 (Unix) mod_ssl/2.2.29 OpenSSL/1.0.1e-fips mod_bwlimited/1.4

Facebook:
Likes:  1
Shares:  16
Comments:  11

Statistics are for the previous month.