dl.yac.mx

Name: Registration Private

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dallas, Texas within the United States which resides on the SoftLayer Technologies Inc. network.
Registrar:
GoDaddy.com

Server location:
Texas, United States (US)

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Root domain:

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ElexdoBrasilParticipacoesa.n, PUP.Elex.YAC (M), PUP.Optional.Installer.W, PUP.Optional.Installer.S, PUP.Optional.Installer.D, PUP.Optional.Installer.ELEX, Threat.Thinknice.Installer, Win32.Generic.ELEX.Installer.Meta, PUP.Elex.Yac.Installer.Meta (M), PUP.Elex.Yac (M)
92.59%

ESET NOD32
Win32/ELEX (variant), Win32/ELEX.AS (variant), Win32/ELEX.BI (variant)
18.52%

Dr.Web
Adware.Mutabaha.99, Adware.Mutabaha.229, Win32.Sector.30
14.81%

AVG
Win.Threat.Medium, Win32/Sality
11.11%

Norman
Suspicious_Gen4.GXEQN, Win32.Sality.3
11.11%

F-Prot
W32/S-72a2296b, W32/Sality.gen2
11.11%

Emsisoft Anti-Malware
Trojan.GenericKD.2078221, Win32.Sality
11.11%

McAfee
Artemis!E322397ABC37, Program.Artemis!0C2BC46DBF42, Program.Artemis!6F62FC863453
11.11%

Antiy Labs AVL
Spyware[AdWare:not-a-virus]/Win32.D365
7.41%

Baidu Antivirus
Adware.Win32.ELEX, Adware.Win32.Elex
7.41%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4721115
7.41%

McAfee Web Gateway
Artemis, BehavesLike.Win32.MultiPlug.cc
7.41%

G Data
Trojan.GenericKD.2078221, Win32.Application.Elex
7.41%

Bkav FE
W32.HfsAdware
7.41%

ESET NOD32
Win32/Sality.NBA virus
7.41%

The domain dl.yac.mx has been seen to resolve to the following 10 IP addresses.

75.126.66.174-static.reverse.softlayer.com
May 30, 2014

75.126.66.173-static.reverse.softlayer.com
May 30, 2014

75.126.66.172-static.reverse.softlayer.com
May 30, 2014

75.126.66.163-static.reverse.softlayer.com
May 30, 2014

75.126.66.162-static.reverse.softlayer.com
May 30, 2014

75.126.20.222-static.reverse.softlayer.com
May 30, 2014

75.126.20.221-static.reverse.softlayer.com
May 30, 2014

75.126.20.219-static.reverse.softlayer.com
May 30, 2014

75.126.134.25-static.reverse.softlayer.com
May 30, 2014

75.126.134.24-static.reverse.softlayer.com
May 30, 2014

File downloads found at URLs served by dl.yac.mx.

1 / 68      (PUP)

1 / 68      (PUP)
http://dl.yac.mx/download/.../yet_another_cleaner_sk.exe  (1d95122a32aa0f019ca166fec08a7e2e)

3 / 68      (PUP)

0 / 68
http://dl.yac.mx/download/.../yac.exe  (41eabd65ece5bf4e66522821774e9d68)

19 / 68    (Adware)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://dl.yac.mx/.../iSafe_setup.exe  (2948122fcf8c8e902cb3eb06327e2718)

10 / 68    (PUP)

12 / 68    (PUP)

1 / 68      (PUP)
http://dl.yac.mx/download/.../dsk.exe  (b0d7ab7054cca0a5d0df30415ccb72ce)

1 / 68      (Malware)

1 / 68      (PUP)

4 / 68      (Adware)

1 / 68      (PUP)
http://dl.yac.mx/.../iSafe_setup_smod.exe  (3da947a6824ac53f92948aa23d076ab6)

 
Latest 30 of 117 download URLs

The following 30 files have been seen to comunicate with dl.yac.mx in live environments.

 
Latest 20 of 69 files

URL:
http://dl.yac.mx/

Web server:
nginx