Malware Distributor
This site is classified as Malware Distributor based on multiple risk signals, including 8 blacklist detections and no established public user-review history. These risks are driven by active warning signals despite the site's longer domain history.
Figure 1. Trust signal radar for softgozar.com. Larger shaded area indicates stronger trust signals.
How we scored softgozar.com
On-page mentions:
Cybersecurity, Games, Microsoft Software
Tech signals:
Web Application
Positive signals:
strong independent trust
a long-term domain history (18.5 years)
an active SSL certificate (3 months)
presence in public traffic rankings
Negative signals:
security-provider warnings
multiple malware or phishing blacklist detections (8)
Context signals:
content related to cybersecurity tools for malware and phishing defense; online gaming
Last checked September 23, 2026 at 7:14 AM by
Gridinsoft Trust Model v2.5.4
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on Softgozar.com
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260903033709-b92654ad
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Distributes Malware or Unwanted File Download
Evidence basis
First-party site analysisExternal vendor intelligence: Context only — not used for this decision
The current Gridinsoft category is retained because the exact reported download chain remains active. The www software pages link to two current RAR archives, and those archives contain the exact reported Windows executables: an AOMEI crack activator and an NTFS Permissions Reporter keymaker. Their included instructions direct users to run the activation-bypass tools, and the AOMEI instructions tell users to whitelist crack files when antivirus software detects them. The files were not executed, so this review does not claim a specific trojan family or payload. The reproducible basis is current distribution of unwanted crack/key-generator executables, not the apex-versus-www spelling difference or external blacklist labels.
Analyst findings
Medium1
Info2
Medium01
Current pages distribute crack and key-generator executables
The reviewed www pages currently link to the reported archives, and each archive contains the exact executable identified by the reporter: an AOMEI activator and an NTFS Permissions Reporter keymaker. The included instructions direct users to run those tools to bypass normal product activation and, for the activator, to whitelist it when antivirus software reacts. This is reproducible current distribution of unwanted executable content.
Info02
The review does not assert a specific trojan payload
The exact current objects and activation-bypass purpose were confirmed, but the executables were not dynamically run. The retained category describes distribution of malware or unwanted-file downloads; it does not claim that this review reproduced a specific trojan family, command chain, or payload.
Info03
The apex and www discrepancy does not invalidate the download evidence
The apex redirects to www, and the www pages actively publish the dl1 and dl2 objects. A separate clean hostname result is not evidence that the current downloadable archives are absent or harmless. The verdict is tied to the exact current file-delivery chain rather than to hostname spelling or external blacklist count.
Review 5 documented observations
View evidence
01Redirect
The apex redirected to https://www.softgozar.com/. The reviewed AOMEI Backupper and NTFS Permissions Reporter pages returned HTTP 200 and directly linked to the two RAR archives named in the report. The hostname difference does not separate the operator page from the download objects because the www pages actively publish the dl1 and dl2 archive links.
HTTP status301
Final URLhttps://www.softgozar.com/
Public artifact URLhttps://www.softgozar.com/aomei-backupper_/
Public artifact URLhttps://www.softgozar.com/ntfs-permissions-reporter_/
Analyst observationBoth reviewed software pages contained live direct links to the reported RAR archives on dl1.softgozar.com and dl2.softgozar.com.
02Download
The current 201,969,592-byte RAR archive was downloaded without execution. It contained an executable named Activator_AOMEI_Backupper_v2.exe whose SHA-256 exactly matched the file object supplied in the report. The archive README instructed the user to run the activator, press Activate, and whitelist crack files when antivirus software detects them.
Analyst observationThe inner matching file was a Windows GUI PE executable in a Crack directory; no executable was launched during this review.
Page elementThe archive README instructed users to run the activator and whitelist crack files if antivirus software detects them.
03Download
The current 60,784,277-byte RAR archive was downloaded without execution. It contained Keymaker/Keymaker.exe whose SHA-256 exactly matched the second file object supplied in the report. The README instructed the user to run Setup.exe and then run the keymaker to obtain a serial number for activation.
Analyst observationThe inner matching file was a Windows console PE executable in a Keymaker directory; no executable was launched during this review.
Page elementThe archive README instructed users to run the keymaker and use the displayed serial number to activate the program.
04Content
Static inspection confirmed that both matching file objects are Windows executables and that neither PE image contains an Authenticode security directory. The activator imports Windows allocation and system libraries. This review did not execute the files or claim a specific malware family, persistence action, command chain, or network payload.
Analyst observationActivator_AOMEI_Backupper_v2.exe is a 32-bit Windows GUI PE; Keymaker.exe is a 64-bit Windows console PE.
Analyst observationBoth executable PE headers had an empty security directory, so no embedded Authenticode signature was present.
Analyst observationThe files were reviewed statically and were not executed; this analysis does not assert a trojan or other specific malware payload.
05Historical content
Public urlscan searches returned 130 records associated with the parent-domain search and 80 for www, including repeated captures of the expected Persian software-download site. The returned result set did not assign a malicious urlscan verdict. OTX reported no pulse for www or dl1 in the available responses, and Wayback preserved extensive www history. These indexes are incomplete and were context only because the live exact downloads already supplied reproducible object-level evidence.
Public artifact URLhttps://urlscan.io/domain/softgozar.com
Public artifact URLhttps://urlscan.io/domain/www.softgozar.com
Public artifact URLhttps://otx.alienvault.com/indicator/domain/softgozar.com
Public artifact URLhttps://web.archive.org/web/*/www.softgozar.com/*
Analyst observationExternal domain labels and public-index coverage were not substituted for the current exact archive and executable evidence.
Scope and limitations
The review covered the apex redirect, the two reported www software pages, the two current RAR archives, their file listings and extracted contents, static PE metadata, DNS, current report data, public URL intelligence, and available archive context.
The executable files were not launched or dynamically sandboxed by Gridinsoft during this review; no specific malware family, persistence behavior, command execution, or network payload is asserted.
Only the two exact reported download objects were downloaded and inspected in depth. Other files, mirrors, software pages, account areas, and future replacements were not exhaustively reviewed.
Public urlscan, OTX, archive, sandbox, and threat-intelligence indexes are finite; unavailable or missing results were treated as unknown rather than clean.
External vendors manage their own current labels. Their results were recorded as context and did not determine this verdict.
What is Softgozar?
Softgozar.com is linked to malware distribution. The typical pattern is a file presented as a normal installer, update, crack, or document tool.
After execution, payloads may steal saved credentials, inject browser scripts, deploy spyware, or drop ransomware components. Damage often happens silently before users notice obvious symptoms.
Figure 2.
Website screenshot for Softgozar.com.
2026-09-23 10:14:09
Do not run executables from this source. If you already did, disconnect the device from sensitive accounts and start incident-response checks immediately.
This domain was registered March 26, 2008 at 2:42 AM through the company CSL Computer Service Langenbach GmbH d/b/a joker.com
and ownership information is not publicly available.
🚨
Gridinsoft blocks this website because it was classified as malware distributor.
softgozar.com should not be treated as a safe website. Gridinsoft gives it a 10/100 trust score, and publicly displayed security sources report 8 warning(s). Avoid entering passwords, personal details, or payment data.
Why is softgozar.com marked "Malware Distributor"?
Gridinsoft evaluates softgozar.com, focusing on suspicious content indicators (Blacklisted by Security Providers, Blacklisted), hosting technology and infrastructure, SSL certificate status, website reputation across multiple databases, customer reviews from various independent platforms. We weigh these indicators to calculate the trust score.
Note: Automated systems are not perfect — while the evidence suggests risk, there is still a chance the site is legitimate. We recommend you check the website using detailed analysis or by contacting the company directly through verified channels.
A structured view of the site's detected themes, page signals, and related online footprint elements.
Cybersecurity
Games
Microsoft Software
Web Application
This site is configured as an installable web application (PWA-style behavior) with app-like interaction patterns.
jQuery Library
Blacklisted by Security Providers
Security intelligence signal: A security-provider signal contributes to the automated assessment of softgozar.com. Publicly displayable provider verdicts, when available, are reported separately; some source details may be restricted by license.
Long Term Domain
softgozar.com is registered for an extended period, which is generally a positive continuity signal.
Established Domain
This site has maintained active domain presence over time, indicating operational continuity.
Listed by Gridinsoft
Gridinsoft Internet Security classified this site as unsafe. As a VirusTotal partner, our detections contribute to broader protection across tools and browsers.
Verified ServicesThis domain has been verified by the following legitimate services and organizations, confirming authentic ownership and proper email security configuration.
Google Verification
Domain ownership verified by Google.
Security FingerprintUnique identifier based on site analysis
If you own Softgozar.com and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about softgozar.com, the fewer chances they have to deceive someone else.Help others evaluate softgozar.com by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about softgozar.com, the fewer chances they have to deceive someone else. Help others evaluate softgozar.com by sharing this page on social media!