download.yontoo.com

Yontoo LLC  (via a Proxy Registrant)

Domain Information

download.yontoo.com is operated by Sambreel's (now QuestPoint) subsidiary Yontoo. The domain download.yontoo.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2007. This domain has been known to host and distribute potentially unwanted software. The hosted servers are located in Broomfield, Colorado within the United States which resides on the Level 3 Communications, Inc. network. The domain is associated with the publisher Yontoo LLC who is located in Carlsbad, California in the United States.
Registrar:
GODADDY.COM, LLC

Server location:
Colorado, United States (US)

Create date:
Friday, March 30, 2007

Expires date:
Wednesday, March 30, 2016

Updated date:
Monday, April 27, 2015

ASN:
AS54761 ARIN-SAMBREEL-SVCS - Sambreel Services, LLC

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

VIPRE Antivirus
Yontoo
100.00%

Reason Heuristics
PUP.Installer.YontooTechnology.V, PUP.Installer.YontooTechnology.R, PUP.Yontoo.YontooTechnology.Installer (M)
100.00%

Norman
Agent.VBAZ.dropper
40.00%

Dr.Web
Adware.Plugin.11
40.00%

Avira AntiVirus
ADWARE/Yontoo.Gen
40.00%

ESET NOD32
Win32/Adware.Yontoo, Win32/Adware.Yontoo (variant)
40.00%

Rising Antivirus
Trojan.InstallRex!562A
40.00%

IKARUS anti.virus
AdWare.Yontoo
40.00%

Trend Micro House Call
TROJ_GEN.R0CBH01GT13
20.00%

The domain download.yontoo.com has been seen to resolve to the following IP address.

May 5, 2015

File downloads found at URLs served by download.yontoo.com.

2 / 68      (Adware)
http://download.yontoo.com/YontooClientSetup.Exe  (0a9118d96054cabf34f4abc4bc8f3659)

9 / 68      (Adware)
http://download.yontoo.com/YontooClientSetup.exe  (d3c1ab47797d24a8db1ce94fd23f0013)

8 / 68      (Adware)
http://download.yontoo.com/YontooClientSetup.exe  (22777f28303b9efd2d3bc9df46d17da0)

2 / 68      (Adware)
http://download.yontoo.com/YontooSetup-DropDownDeals.exe  (230f2a77e80b6a423f4695df95736ed0)

2 / 68      (Adware)
http://download.yontoo.com/YontooClientSetup.Exe  (8bcfed8d826fac7ad2440d74aa5e8336)

The following 576 files have been seen to comunicate with download.yontoo.com in live environments.

 
Latest 20 of 576 files

URL:
http://download.yontoo.com/

Title:
“Untitled Page”

SSL certificate subject:
CN=*.yontoo.com, OU=Domain Control Validated

SSL certificate issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc."

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)

30 of 37 related domains