install.yulasee.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain install.yulasee.com is registered by proxy through GODADDY.COM, LLC and was originally registered in March of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Atlanta, Georgia within the United States which resides on the Cox Communications Inc. network.
Registrar:
GODADDY.COM, LLC

Server location:
Georgia, United States (US)

Create date:
Tuesday, March 18, 2014

Expires date:
Saturday, March 18, 2017

Updated date:
Saturday, March 19, 2016

ASN:
AS54761 ARIN-SAMBREEL-SVCS - Sambreel Services, LLC,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Yula.S, PUP.Yula.Q, PUP.Yontoo.Yula (M)
100.00%

VIPRE Antivirus
Threat.4741131
66.67%

Dr.Web
Trojan.BPlug.95
66.67%

AVG
nbsp;
66.67%

ESET NOD32
MSIL/BrowseFox (variant)
33.33%

ESET NOD32
probably MSIL/BrowseFox.G potentially unwanted application
33.33%

McAfee
Trojan.Artemis!E48BE5A4D7E6
33.33%

The domain install.yulasee.com has been seen to resolve to the following 2 IP addresses.

April 1, 2016

wsip-70-186-131-82.sd.sd.cox.net
August 12, 2014

File downloads found at URLs served by install.yulasee.com.

1 / 68      (Adware)
http://install.yulasee.com/ud  (yulaseeuninstaller.exe)

6 / 68      (Adware)
http://install.yulasee.com/ud  (Yula Uninstaller.exe)

5 / 68      (Adware)
http://install.yulasee.com/ud  (yulaseeuninstaller.exe)

URL:
http://install.yulasee.com/

SSL certificate subject:
CN=*.yulasee.com

SSL certificate issuer:
CN=RapidSSL SHA256 CA, O=GeoTrust Inc., C=US

Web server:
Microsoft-IIS/7.5 (ASP.NET)