www.performersoft.com

Performersoft LLC

Domain Information

The domain www.performersoft.com registered by iBario LTD was initially registered in April of 2010 through Moniker Online Services. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Washington, Virginia within the United States which resides on the SoftLayer Technologies Inc. network. The domain is associated with the publisher Performersoft LLC who is located in Beaverton, Oregon in the United States.
Remove Malware from www.performersoft.com - Powered by Reason Core Security
Registrar:
Moniker Online Services

Server location:
Virginia, United States (US)

Create date:
Wednesday, April 14, 2010

Expires date:
Thursday, April 14, 2016

Updated date:
Friday, December 18, 2015

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Performersoft.AA, PUP.Installer.Performersoft.Q, PUP.Installer.Performersoft.U, PUP.Installer.Performersoft.Y, PUP.Installer.Performersoft.R
100.00%

Avira AntiVirus
APPL/InstallBrain.Gen5, TR/Strictor.13903.1, ADWARE/Adware.Gen7
85.71%

Comodo Security
ApplicUnwnt.Win32.AdWare.IBrain.B
71.43%

VIPRE Antivirus
InstallBrain
71.43%

ESET NOD32
Win32/InstallBrain (variant)
71.43%

Dr.Web
Adware.Downware.371
57.14%

Fortinet FortiGate
Adware/Fam.NB, Riskware/InstallBrain, Adware/InstallBrain, Adware/Sofagn
57.14%

F-Prot
W32/IBrain.B.gen, W32/IBrain.B2.gen
57.14%

Sophos
InstallBrain
57.14%

Microsoft Security Essentials
TrojanDownloader:Win32/Brantall.A, TrojanDownloader:Win32/Brantall.E
57.14%

Panda Antivirus
PUP/Ibups, Adware/Ibups
57.14%

MicroWorld eScan
ADWARE/InstallBrain.Gen, Application.Bundler.InstallBrain.A
42.86%

IKARUS anti.virus
Trojan-Downloader.Win32.Brantall, Luhe.InstallBrain
42.86%

AVG
Luhe.InstallBrain.A
42.86%

K7 AntiVirus
Unwanted-Program
42.86%

The domain www.performersoft.com has been seen to resolve to the following 12 IP addresses.

50.97.57.37-static.reverse.softlayer.com
February 3, 2016

50.23.135.221-static.reverse.softlayer.com
February 3, 2016

208.43.224.240-static.reverse.softlayer.com
January 17, 2014

108.168.162.216-static.reverse.softlayer.com
January 17, 2014

208.43.244.224-static.reverse.softlayer.com
January 17, 2014

208.43.249.112-static.reverse.softlayer.com
January 17, 2014

50.97.40.168-static.reverse.softlayer.com
January 17, 2014

50.97.57.32-static.reverse.softlayer.com
January 17, 2014

50.97.56.104-static.reverse.softlayer.com
January 17, 2014

184.173.139.224-static.reverse.softlayer.com
January 17, 2014

208.43.236.200-static.reverse.softlayer.com
January 17, 2014

208.43.230.160-static.reverse.softlayer.com
January 17, 2014

File downloads found at URLs served by www.performersoft.com.

19 / 68    (PUP)
http://www.performersoft.com/.../DriverPerformer_J.exe  (9119a79b4fca83effc0193ea21b9a6a2)

9 / 68      (PUP)
http://www.performersoft.com/.../pcperformer_st.exe  (install pc performer153218.exe)

28 / 68    (PUP)
http://www.performersoft.com/.../PCPerformer_inc.exe  (b8922dfbf6e97834c12098c5fb1c824f)

3 / 68      (Adware)

9 / 68      (PUP)

30 / 68    (PUP)

1 / 68      (PUP)
http://www.performersoft.com/.../PCPerformer_J13o.exe  (c576451696baabc76e5eb2c8c84b046e)

The following 2 files have been seen to comunicate with www.performersoft.com in live environments.

URL:
http://www.performersoft.com/

Google Analytics:
UA-42277600

Title:
“PerformerSoft”

Web server:
nginx (PHP/5.4.17)

Facebook:
Likes:  12,947
Shares:  45
Comments:  8

Statistics are for the previous month.

Remove Malware from www.performersoft.com - Powered by Reason Core Security