www.yac.mx

Name: Registration Private

Domain Information

This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Washington, District of Columbia within the United States which resides on the ThePlanet.com Internet Services, Inc. network.
Registrar:
GoDaddy.com

Server location:
District of Columbia, United States (US)

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.W, PUP.Optional.ElexdoBrasilParticipacoesa.T, PUP.Optional.Installer.Y, PUP.Optional.Installer.ELEX, Win32.Generic.Installer.ELEX.Meta, Win32.Generic.ELEX.Installer.Meta, PUP.Elex.YAC.Meta (M), PUP.Elex.Yac.Installer.Meta (M), PUP.Elex.YAC (M), PUP.Elex.Yac (M), Threat.Win.Reputation.IMP
100.00%

Trend Micro House Call
TROJ_GEN.F47V0422, ADW_ELEX, Suspicious_GEN.F47V1115, Suspicious_GEN.F47V0511, Suspicious_GEN.F47V0527, Suspicious_GEN.F47V0330
15.22%

Malwarebytes
PUP.Optional.Elex, PUP.Optional.ELEX, Fraudtool.YAC
15.22%

Dr.Web
Adware.Mutabaha.45, Adware.Mutabaha.73, Adware.Mutabaha.113, Adware.Mutabaha.174, Adware.Mutabaha.163, Adware.Mutabaha.456
13.04%

ESET NOD32
Win32/ELEX (variant), Win32/ELEX.CC potentially unwanted (variant)
10.87%

Bkav FE
W32.Clode48.Trojan, W32.HfsAdware
10.87%

IKARUS anti.virus
Trojan-Dropper, PUA.Elex
8.70%

McAfee
Artemis!B3B888FC206C, Artemis!6AF75BDEC524, Artemis!1D1DD21ED816
6.52%

Avira AntiVirus
ADWARE/Adware.Gen2, TR/Elex.1139232
6.52%

Fortinet FortiGate
Riskware/Elex
6.52%

Panda Antivirus
PUP/YAC
6.52%

Baidu Antivirus
Adware.Win32.ELEX
4.35%

K7 AntiVirus
Unwanted-Program , Adware
4.35%

Kaspersky
not-a-virus:Downloader.Win32.Agent, not-a-virus:Downloader.Win32.Elex
4.35%

NANO AntiVirus
Trojan.Win32.Elex.cumwmi, Riskware.Nsis.Mutabaha.dqgtqu
4.35%

The domain www.yac.mx has been seen to resolve to the following 4 IP addresses.

174.36.247.66-static.reverse.softlayer.com
May 13, 2014

184.173.128.178-static.reverse.softlayer.com
March 14, 2014

184.173.128.179-static.reverse.softlayer.com
March 14, 2014

173.192.211.213-static.reverse.softlayer.com
November 21, 2013

File downloads found at URLs served by www.yac.mx.

1 / 68      (Malware)
http://www.yac.mx/download/.../down.php?pt=reh  (yet_another_cleaner_reh.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=mcr  (yet_another_cleaner_mcr.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=ava&subid=10019436845  (yet_another_cleaner_ava_setup_10019436845.exe)

1 / 68      (PUP)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=mar  (yet_another_cleaner_mar.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=rkla&subid=5253  (yet_another_cleaner_rkla_setup_5253.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=smo  (yet_another_cleaner_smo.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=gam  (yet_another_cleaner_gam.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=mma  (yet_another_cleaner_mma.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=mat  (yet_another_cleaner_mat.exe)

1 / 68      (PUP)
http://www.yac.mx/.../5695750  (yet_another_cleaner_sk_5695750.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=ava  (yet_another_cleaner_ava.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=nvba  (yet_another_cleaner_nvba.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=avae  (yet_another_cleaner_avae.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=cdls&subid=13721  (yet_another_cleaner_cdls_setup_13721.exe)

1 / 68      (PUP)
http://www.yac.mx/download/ps/.../yet_another_cleaner.exe  (6a157e53fd85531f56edd26366db7016)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=sim&subid=434302863  (yet_another_cleaner_sim_setup_428918017.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=avae&subid=9883648401  (yet_another_cleaner_sim_setup_428918017.exe)

1 / 68      (PUP)

3 / 68      (PUP)
http://www.yac.mx/.../3300514  (yet_another_cleaner_sk_0.exe)

5 / 68      (PUP)
http://www.yac.mx/download/ad/en/.../yet_another_cleaner.exe  (e54e43956e4680101b9a09c969075a8dc6fcf76a.svn-base)

15 / 68    (PUP)
http://www.yac.mx/download/.../down.php?pt=ymb&subid=16100  (yet_another_cleaner_mat_setup_152743.exe)

4 / 68      (PUP)

2 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=sim&subid=424398246  (yet_another_cleaner_sim_setup_424312783.exe)

3 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=brof  (yet_another_cleaner_matf.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=bro  (yet_another_cleaner_bro.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=nva&subid=3841853212  (yet_another_cleaner_nva_setup_3831223861.exe)

1 / 68      (PUP)
http://www.yac.mx/download/.../down.php?pt=cdla  (yet_another_cleaner_cdla.exe)

6 / 68      (PUP)

 
Latest 30 of 2,554 download URLs

The following 120 files have been seen to comunicate with www.yac.mx in live environments.

 
Latest 20 of 171 files

URL:
http://www.yac.mx/

Google Analytics:
UA-40676322

Title:
“Yet Another PC Cleaner | Lifetime Free PC Cleaner - YAC Official Website”

Description:
“YAC PC Cleaner, The Lightest & Fastest Cleaner, available for Windows 8, 7, Vista, and XP. Choose the ONE or nothing”

SSL certificate subject:
CN=www.yac.mx, OU=Domain Control Validated

SSL certificate issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc."

Web server:
ngx_openresty (ThinkPHP)

Facebook:
Likes:  1,424
Shares:  1,559
Comments:  652

Compete.com:
US visitors:  75,474

Statistics are for the previous month.