ads.illyx.com

Domains By Proxy, LLC  (Proxy Registrant)

Domain Information

The domain ads.illyx.com is registered by proxy through GODADDY.COM, LLC and was originally registered in October of 2011. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Dublin, Dublin City within Ireland which resides on the Amazon Technologies Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the EU (Ireland) region datacenter.
Registrar:
GODADDY.COM, LLC

Server location:
Dublin City, Ireland (IE)

Create date:
Tuesday, October 11, 2011

Expires date:
Saturday, October 11, 2014

Updated date:
Tuesday, August 14, 2012

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Kreapixel.M, PUP.Installer.Kreapixel.J
100.00%

McAfee
Artemis!1A001C0A48CB
50.00%

K7 AntiVirus
Unwanted-Program
50.00%

Trend Micro House Call
TROJ_GEN.F47V0306
50.00%

Sophos
Kreapixel
50.00%

VIPRE Antivirus
Trojan.Win32.Generic
50.00%

G Data
Win32.Application.KreaPixWebplayer
50.00%

ESET NOD32
Win32/AdWare.Illyx
50.00%

IKARUS anti.virus
Trojan-Downloader.Win32.Genome
50.00%

Fortinet FortiGate
Riskware/Illyx
50.00%

herdProtect (fuzzy)
a variant of f1af82752613237d9029c8c926e48a0a84a126d6
50.00%

Avira AntiVirus
TR/Patched.Ren.Gen
50.00%

The domain ads.illyx.com has been seen to resolve to the following 4 IP addresses.

ec2-50-18-211-52.us-west-1.compute.amazonaws.com
September 3, 2014

ec2-54-229-12-122.eu-west-1.compute.amazonaws.com
April 16, 2014

ec2-54-246-131-211.eu-west-1.compute.amazonaws.com
April 16, 2014

ec2-54-246-131-227.eu-west-1.compute.amazonaws.com
April 16, 2014

File downloads found at URLs served by ads.illyx.com.

1 / 68      (PUP)

12 / 68    (PUP)

The following file have been seen to comunicate with ads.illyx.com in live environments.

URL:
http://ads.illyx.com/

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx/1.4.4