Gridinsoft Logo

Softgozar.com Malware Distributor

September 23, 2026 at 7:14 AM
Malware Distributor
Checked by Website Reputation Checker
Table of Contents
Danger Zone
Risky Territory
Caution Advised
Trusted but Verify
Safe & Secure

Softgozar → Safety Check

First checked October 4, 2025 at 6:16 AM
Website content and technical signals analyzed
Method: automated checks.
Malware Distributor This site is classified as Malware Distributor based on multiple risk signals, including 8 blacklist detections and no established public user-review history. These risks are driven by active warning signals despite the site's longer domain history.
Trust signal radar Normalized trust signals for softgozar.com Domain Maturity: 6755 days Domain Maturity Warning Cleanliness: 8 detections Warning Cleanliness Safety Level: 2 negative tags Safety Level Positive Signals: 2 positive signals Positive Signals Popularity: Tranco rank 339,828 Popularity Trust Zone: .com Trust Zone Operational Signals: 1 detected services Operational Signals Location Credibility: Hosting country CA Location Credibility
Figure 1. Trust signal radar for softgozar.com. Larger shaded area indicates stronger trust signals.

How we scored softgozar.com

On-page mentions:
Cybersecurity, Games, Microsoft Software
Tech signals:
Web Application
Positive signals:
  • strong independent trust
  • a long-term domain history (18.5 years)
  • an active SSL certificate (3 months)
  • presence in public traffic rankings
Negative signals:
  • security-provider warnings
  • multiple malware or phishing blacklist detections (8)
Context signals:
  • content related to cybersecurity tools for malware and phishing defense; online gaming
Last checked September 23, 2026 at 7:14 AM by Gridinsoft Trust Model v2.5.4
Independent Gridinsoft analysis

What Gridinsoft observed on Softgozar.com

A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.

Current review Review ID GMA-20260903033709-b92654ad
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Distributes Malware or Unwanted File Download
Evidence basis
First-party site analysis External vendor intelligence: Context only — not used for this decision

The current Gridinsoft category is retained because the exact reported download chain remains active. The www software pages link to two current RAR archives, and those archives contain the exact reported Windows executables: an AOMEI crack activator and an NTFS Permissions Reporter keymaker. Their included instructions direct users to run the activation-bypass tools, and the AOMEI instructions tell users to whitelist crack files when antivirus software detects them. The files were not executed, so this review does not claim a specific trojan family or payload. The reproducible basis is current distribution of unwanted crack/key-generator executables, not the apex-versus-www spelling difference or external blacklist labels.

Analyst findings

  • Medium 1
  • Info 2
  1. Medium

    Current pages distribute crack and key-generator executables

    The reviewed www pages currently link to the reported archives, and each archive contains the exact executable identified by the reporter: an AOMEI activator and an NTFS Permissions Reporter keymaker. The included instructions direct users to run those tools to bypass normal product activation and, for the activator, to whitelist it when antivirus software reacts. This is reproducible current distribution of unwanted executable content.

  2. Info

    The review does not assert a specific trojan payload

    The exact current objects and activation-bypass purpose were confirmed, but the executables were not dynamically run. The retained category describes distribution of malware or unwanted-file downloads; it does not claim that this review reproduced a specific trojan family, command chain, or payload.

  3. Info

    The apex and www discrepancy does not invalidate the download evidence

    The apex redirects to www, and the www pages actively publish the dl1 and dl2 objects. A separate clean hostname result is not evidence that the current downloadable archives are absent or harmless. The verdict is tied to the exact current file-delivery chain rather than to hostname spelling or external blacklist count.

Review 5 documented observations View evidence
01 Redirect

The apex redirected to https://www.softgozar.com/. The reviewed AOMEI Backupper and NTFS Permissions Reporter pages returned HTTP 200 and directly linked to the two RAR archives named in the report. The hostname difference does not separate the operator page from the download objects because the www pages actively publish the dl1 and dl2 archive links.

  • HTTP status 301
  • Final URL https://www.softgozar.com/
  • Public artifact URL https://www.softgozar.com/aomei-backupper_/
  • Public artifact URL https://www.softgozar.com/ntfs-permissions-reporter_/
  • Analyst observation Both reviewed software pages contained live direct links to the reported RAR archives on dl1.softgozar.com and dl2.softgozar.com.
02 Download

The current 201,969,592-byte RAR archive was downloaded without execution. It contained an executable named Activator_AOMEI_Backupper_v2.exe whose SHA-256 exactly matched the file object supplied in the report. The archive README instructed the user to run the activator, press Activate, and whitelist crack files when antivirus software detects them.

  • HTTP status 200
  • MIME type application/x-rar-compressed
  • File SHA-256 d0ac6f4a906581f48fb7128cbcb5f1ace497f165957d3853eec43ef702d49bdd
  • File SHA-256 2018276745591a2cfa364436a39280a6efb393b879da12db86e302be1bd75d33
  • Analyst observation The inner matching file was a Windows GUI PE executable in a Crack directory; no executable was launched during this review.
  • Page element The archive README instructed users to run the activator and whitelist crack files if antivirus software detects them.
03 Download

The current 60,784,277-byte RAR archive was downloaded without execution. It contained Keymaker/Keymaker.exe whose SHA-256 exactly matched the second file object supplied in the report. The README instructed the user to run Setup.exe and then run the keymaker to obtain a serial number for activation.

  • HTTP status 200
  • MIME type application/x-rar-compressed
  • File SHA-256 b11afd84cf669059d759c4e3510ed81428740398e3ca21509ff3c3af51ce4a0e
  • File SHA-256 7365f35b5ce26a9756dd5aa732f942806dc182f2db3c009fc2da3b8b76cf3364
  • Analyst observation The inner matching file was a Windows console PE executable in a Keymaker directory; no executable was launched during this review.
  • Page element The archive README instructed users to run the keymaker and use the displayed serial number to activate the program.
04 Content

Static inspection confirmed that both matching file objects are Windows executables and that neither PE image contains an Authenticode security directory. The activator imports Windows allocation and system libraries. This review did not execute the files or claim a specific malware family, persistence action, command chain, or network payload.

  • Analyst observation Activator_AOMEI_Backupper_v2.exe is a 32-bit Windows GUI PE; Keymaker.exe is a 64-bit Windows console PE.
  • Analyst observation Both executable PE headers had an empty security directory, so no embedded Authenticode signature was present.
  • Analyst observation The files were reviewed statically and were not executed; this analysis does not assert a trojan or other specific malware payload.
05 Historical content

Public urlscan searches returned 130 records associated with the parent-domain search and 80 for www, including repeated captures of the expected Persian software-download site. The returned result set did not assign a malicious urlscan verdict. OTX reported no pulse for www or dl1 in the available responses, and Wayback preserved extensive www history. These indexes are incomplete and were context only because the live exact downloads already supplied reproducible object-level evidence.

  • Public artifact URL https://urlscan.io/domain/softgozar.com
  • Public artifact URL https://urlscan.io/domain/www.softgozar.com
  • Public artifact URL https://otx.alienvault.com/indicator/domain/softgozar.com
  • Public artifact URL https://web.archive.org/web/*/www.softgozar.com/*
  • Analyst observation External domain labels and public-index coverage were not substituted for the current exact archive and executable evidence.

Scope and limitations

  • The review covered the apex redirect, the two reported www software pages, the two current RAR archives, their file listings and extracted contents, static PE metadata, DNS, current report data, public URL intelligence, and available archive context.
  • The executable files were not launched or dynamically sandboxed by Gridinsoft during this review; no specific malware family, persistence behavior, command execution, or network payload is asserted.
  • Only the two exact reported download objects were downloaded and inspected in depth. Other files, mirrors, software pages, account areas, and future replacements were not exhaustively reviewed.
  • Public urlscan, OTX, archive, sandbox, and threat-intelligence indexes are finite; unavailable or missing results were treated as unknown rather than clean.
  • External vendors manage their own current labels. Their results were recorded as context and did not determine this verdict.

What is Softgozar?

Softgozar.com is linked to malware distribution. The typical pattern is a file presented as a normal installer, update, crack, or document tool.

After execution, payloads may steal saved credentials, inject browser scripts, deploy spyware, or drop ransomware components. Damage often happens silently before users notice obvious symptoms.

Figure 2. Website screenshot for Softgozar.com. 2026-09-23 10:14:09

Do not run executables from this source. If you already did, disconnect the device from sensitive accounts and start incident-response checks immediately.

This domain was registered March 26, 2008 at 2:42 AM through the company CSL Computer Service Langenbach GmbH d/b/a joker.com and ownership information is not publicly available.

Is softgozar.com safe?

— Unfortunately, not likely.

🚨 Gridinsoft blocks this website because it was classified as malware distributor.

softgozar.com should not be treated as a safe website. Gridinsoft gives it a 10/100 trust score, and publicly displayed security sources report 8 warning(s). Avoid entering passwords, personal details, or payment data.

Why is softgozar.com marked "Malware Distributor"?

Gridinsoft evaluates softgozar.com, focusing on suspicious content indicators (Blacklisted by Security Providers, Blacklisted), hosting technology and infrastructure, SSL certificate status, website reputation across multiple databases, customer reviews from various independent platforms. We weigh these indicators to calculate the trust score.

Note: Automated systems are not perfect — while the evidence suggests risk, there is still a chance the site is legitimate. We recommend you check the website using detailed analysis or by contacting the company directly through verified channels.

Softgozar Digital Footprints

A structured view of the site's detected themes, page signals, and related online footprint elements.

Cybersecurity
Games
Microsoft Software
Web Application

This site is configured as an installable web application (PWA-style behavior) with app-like interaction patterns.

jQuery Library
Blacklisted by Security Providers

Security intelligence signal: A security-provider signal contributes to the automated assessment of softgozar.com. Publicly displayable provider verdicts, when available, are reported separately; some source details may be restricted by license.

Long Term Domain

softgozar.com is registered for an extended period, which is generally a positive continuity signal.

Established Domain

This site has maintained active domain presence over time, indicating operational continuity.

Listed by Gridinsoft

Gridinsoft Internet Security classified this site as unsafe. As a VirusTotal partner, our detections contribute to broader protection across tools and browsers.

Color Guide
  • Requires special attention Marks high-risk findings that should be reviewed first.
  • Exercise caution Highlights areas involving user data, payments, or permissions.
  • Positive indicators Shows trust signals that support the site's reliability.
  • Neutral General context that does not increase or reduce risk on its own.

External provider warnings: 8/29 Malware Distributor

This section shows what independent external security sources say about this site.

A warning appears when one or more sources report malware, phishing, abuse, or other safety concerns. Each row shows the source and its verdict.

If no source reports a warning, the site is shown as clear in this section.

ADMINUSLabs
Malicious
alphaMountain.ai
Malicious
Chong Lua Dao
Malicious
Dr.Web
Malicious
ESET
Malware
Lionic
Malicious
Quttera
Malicious
VIPRE
Malware

External provider results for Softgozar.com, last checked September 23, 2026. — VirusTotal

Domain Information

Created March 26, 2008 at 2:42 AM Updated: July 22, 2026 at 1:05 PM · Expires: March 26, 2033 at 2:42 AM
Domain Age 18.5 years
Registrant CA (Canada)
Registrar CSL Computer Service Langenbach GmbH d/b/a joker.com IANA ID: 113
Abuse Email [email protected]
Domain Status Client Transfer Prohibited DNSSEC: UNSIGNED
Top Level Domain .com Generic TLD

Technical Details

HTTP status 301
IP Address 185.208.173.17
Hosting Provider BitCommand LLC London, England, GB · Hosting Provider · Anycast
Network AS202269 - BitCommand LLC Hosting
SSL Certificate YR1 TLS 1.3 · Valid for: 3 months · from July 22, 2026 at 2:41 PM · to October 20, 2026 at 2:41 PM
Name Servers breeze.parspack.net
peninsula.parspack.net

Content Analysis

Website title سافت گذر دانشنامه نرم افزار - دانلود رایگان نرم افزار
Website description .سافت گذر اولین دانشنامه نرم افزار ایران است که امکان دانلود رایگان نرم افزار، بازی، کتاب الکترونیکی، برنامه های موبای�...
Primary Language
Mentioned hosts (13)
biscotti.yektanet.com www.esetupdate.ir events.najva.com van.najva.com www.softgozar.com ua.yektanet.com cdn.yektanet.com eitaa.com www.aparat.com fonts.googleapis.com softgozar.com audience.yektanet.com esetupdate.ir

Security Analysis

Detection Signatures These signatures are used to generate the security fingerprint below.
Cybersecurity Games Microsoft Software Web Application jQuery Library
Verified Services This domain has been verified by the following legitimate services and organizations, confirming authentic ownership and proper email security configuration.
Google Verification Domain ownership verified by Google.
Security Fingerprint Unique identifier based on site analysis

How to block Softgozar.com?

Our Anti-Malware can automatically block access to softgozar.com if it is flagged as malicious.

  1. Install and run the protection.
  2. The program will block flagged domains and remove related threats.

Exclusion

If you believe softgozar.com is safe, you can add it to the exclusion list:

  1. Open Gridinsoft Anti-Malware → Tools → Ignore List.
  2. Go to the Internet tab and add softgozar.com.

See detailed instructions for more options.

Are You the Owner?

If you own Softgozar.com and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.

Leave a review

Share your real experience with softgozar.com. Is it a trustworthy site, or did you encounter any issues? The more detail you provide, the more helpful your review is for others!

Publication Tip

- Your feedback helps us improve our security scores.
- Detailed reviews describing your real-life experience have a much higher chance of being published.
- Your email remains confidential.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your score for softgozar.com
10
points /100
The score is based on a 1-100 scale, with 100 being the most reputable.
Check another website
Verify the security of domains and services based on 10M+ real websites.
Is This Your Website?
Think your website was scored unfairly? Request a reevaluation and our team will take another look.
Flag for Reevaluation
Have you had a personal experience with Softgozar.com?
Share your thoughts and rate it to help others make informed decisions!
Is This Your Website?
Think your website was scored unfairly? Request a reevaluation and our team will take another look.
Flag for Reevaluation
Have you had a personal experience with Softgozar.com?
Share your thoughts and rate it to help others make informed decisions!