Locky C2 ::

Host Information

Locky C2:
Host Status:offline
Firstseen (UTC):2016-09-12 17:07:49
Lastseen (UTC):2016-09-18 10:32:04

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky C2. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
yes2016-09-20 11:48:082016-10-18 15:13:1751.255.105.2ip2.ip-51-255-105.euNot listedAS16276OVH , FR- France (FR)

# IPs found: 1 (max. 25)

Referencing malware samples

Latest 100 malware binaries referencing this Locky C2:

Firstseen (UTC)MD5 hashFilesizeVTLocky C2 URL
2016-09-16 15:21:2192cc7704c70318274870cca30f084a8a225'365 bytesVirustotal results 28/57 (49.12%)
2016-09-16 06:14:25fa7010e409f69f0007f2c29fb03c1dc7170'496 bytesVirustotal results 9/57 (15.79%)
2016-09-14 10:23:03f41adf2ecdb3e659b7f1e179837bb8cc266'752 bytesn/ahttp://
2016-09-13 23:20:48ab8c9ffaa2b96dce59be387fe17d426d205'279 bytesVirustotal results 10/58 (17.24%)
2016-09-13 22:33:4419504d96584291023f8a183d416a4a1c221'272 bytesVirustotal results 4/57 (7.02%)
2016-09-13 15:42:4809a8f5bdd28ffe8f058b69a709546a51264'192 bytesVirustotal results 8/57 (14.04%)
2016-09-12 14:25:28c847e341d435a45497b47d04067cfb2e263'680 bytesVirustotal results 7/57 (12.28%)

Referencing malware samples: 7