www.softologica.com

Felix Leshno felix@net-monster.biz

Domain Information

The domain www.softologica.com registered by Felix Leshno felix@net-monster.biz was initially registered in October of 2012 through Moniker Online Services. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the SoftLayer Technologies Inc. network.
Registrar:
Moniker Online Services

Server location:
Texas, United States (US)

Create date:
Tuesday, October 30, 2012

Expires date:
Thursday, October 30, 2014

Updated date:
Thursday, October 10, 2013

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.R2D2TechSoftware.Q, PUP.Performersoft.Bundler (M), PUP.Performersoft.YellowSo.Bundler (M)
100.00%

Dr.Web
Adware.Downware.2543
33.33%

VIPRE Antivirus
InstallBrain
33.33%

ESET NOD32
Win32/InstallBrain.BW (variant)
33.33%

AVG
MalSign.InstallC
33.33%

Malwarebytes
PUP.Optional.CodecPerformer.A
33.33%

Comodo Security
Application.Win32.InstallBrain.BF
33.33%

MicroWorld eScan
Gen:Variant.Jaik.1231
33.33%

Bitdefender
Gen:Variant.Jaik.1231
33.33%

Lavasoft Ad-Aware
Gen:Variant.Jaik.1231
33.33%

Emsisoft Anti-Malware
Gen:Variant.Jaik.1231
33.33%

G Data
Gen:Variant.Jaik.1231
33.33%

Agnitum Outpost
PUA.InstallBrain
33.33%

Sophos
InstallBrain
33.33%

The domain www.softologica.com has been seen to resolve to the following 4 IP addresses.

174.37.181.30-static.reverse.softlayer.com
April 13, 2014

173.192.190.226-static.reverse.softlayer.com
April 13, 2014

50.97.44.130-static.reverse.softlayer.com
April 13, 2014

50.97.49.242-static.reverse.softlayer.com
April 13, 2014

File downloads found at URLs served by www.softologica.com.

The following 18 files have been seen to comunicate with www.softologica.com in live environments.

 
Latest 20 of 23 files

URL:
http://www.softologica.com/

Title:
“Contact Us”

Web server:
nginx/1.2.4 (PHP/5.3.16)