Locky Distribution Site :: autoecole-jeanpierre.com

Host Information

Locky Distribution Site:autoecole-jeanpierre.com
Threat:Distribution Site
Malware:Locky
URL:http://autoecole-jeanpierre.com/jhbvDjs0267
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:Gandi SAS
Nameserver(s):ns1.brainydns.com
 ns2.brainydns.com
Firstseen (UTC):2017-09-01 10:08:31
Lastseen (UTC):

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
yes2019-09-03 06:21:382019-09-17 06:18:44162.210.196.166Not listedAS30633LEASEWEB-USA-WDC-01 - Leaseweb USA, Inc.[...]- United States (US)
no2019-08-22 06:18:58never94.229.72.122no.rdns.ukservers.comNot listedAS42831UKSERVERS-AS UK Dedicated Servers, Hosti[...]- United Kingdom (GB)
no2019-08-28 06:19:222019-09-14 06:19:35109.201.133.69Not listedAS43350NFORCE, NL- Netherlands (NL)
no2019-08-27 06:18:47never78.41.204.35server368.snel.comNot listedAS62370SNEL, NL- Netherlands (NL)
no2019-09-16 06:21:10never78.41.204.33server368.snel.comNot listedAS62370SNEL, NL- Netherlands (NL)
no2019-09-05 06:20:50never78.41.204.32server368.snel.comNot listedAS62370SNEL, NL- Netherlands (NL)
no2019-09-15 06:19:47never78.41.204.29server368.snel.comNot listedAS62370SNEL, NL- Netherlands (NL)
no2019-09-07 06:20:25never78.41.204.26server368.snel.comNot listedAS62370SNEL, NL- Netherlands (NL)
no2019-08-18 06:23:192019-08-19 06:20:3952.0.217.44ec2-52-0-217-44.compute-1.amazonaws.comNot listedAS14618AMAZON-AES - Amazon.com, Inc., US- United States (US)
no2019-09-09 06:19:08never37.48.65.155Not listedAS60781LEASEWEB-NL-AMS-01 Netherlands, NL- Netherlands (NL)
no2019-08-31 06:20:402019-09-06 06:17:1937.48.65.154Not listedAS60781LEASEWEB-NL-AMS-01 Netherlands, NL- Netherlands (NL)
no2019-08-21 06:20:13never37.48.65.153Not listedAS60781LEASEWEB-NL-AMS-01 Netherlands, NL- Netherlands (NL)
no2019-08-24 06:22:01never37.48.65.152Not listedAS60781LEASEWEB-NL-AMS-01 Netherlands, NL- Netherlands (NL)
no2019-08-25 06:20:212019-08-26 06:20:0737.48.65.145Not listedAS60781LEASEWEB-NL-AMS-01 Netherlands, NL- Netherlands (NL)
no2019-08-29 06:20:132019-09-11 06:18:0237.48.65.136Not listedAS60781LEASEWEB-NL-AMS-01 Netherlands, NL- Netherlands (NL)
no2018-06-12 02:02:422019-05-27 06:23:42217.70.184.38webredir.vip.gandi.netNot listedAS29169GANDI-AS Domain name registrar - http://[...]- France (FR)
no2019-08-23 06:18:07never209.126.123.13static-ip-209-126-123-13.inaddr.ip-pool.comNot listedAS30083HEG-US - HEG US Inc., US- United States (US)
no2019-09-01 06:21:422019-09-10 06:21:02209.126.123.12static-ip-209-126-123-12.inaddr.ip-pool.comNot listedAS30083HEG-US - HEG US Inc., US- United States (US)
no2019-09-08 06:20:03never207.244.65.58Not listedAS30633LEASEWEB-USA-WDC-01 - Leaseweb USA, Inc.[...]- United States (US)
no2019-09-04 06:24:242019-09-12 06:19:58199.115.116.216Not listedAS30633LEASEWEB-USA-WDC-01 - Leaseweb USA, Inc.[...]- United States (US)
no2017-09-01 10:08:312017-10-05 04:06:32193.227.248.241193.227.248.241.static.not.updated.as8218.euNot listedAS8218- France (FR)
no2017-10-06 01:42:322018-06-11 01:59:38178.20.66.207edi-01.ovea.comNot listedAS29608WAN2MANY-AS, FR- France (FR)
no2019-08-30 06:18:02never162.222.213.199Not listedAS8100ASN-QUADRANET-GLOBAL - QuadraNet Enterpr[...]- United States (US)
no2019-09-02 06:22:34never162.210.199.87Not listedAS30633LEASEWEB-USA-WDC-01 - Leaseweb USA, Inc.[...]- United States (US)

# IPs found: 24 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2017-09-14 07:16:34a39bd987d0c0a4aea293ddd64600ec6b920'393 bytesVirustotal results 33/60 (55.00%) n/a
2017-09-13 08:09:13218d317505e624ff3435e9fa317d3a02924'389 bytesVirustotal results 27/62 (43.55%) n/a
2017-09-12 11:45:24484acfd7289ddaa4aebc255aa819143f11'281 bytesVirustotal results 15/59 (25.42%) n/a
2017-09-12 10:04:11087de46d1610259c55b51514bc61a14b900'300 bytesVirustotal results 5/61 (8.20%) n/a
2017-09-08 19:09:220a20c7cc0cbb5c6b735646f0c65c70aa908'686 bytesVirustotal results 33/61 (54.10%) n/a
2017-09-07 22:18:412845ffea89a6f8c52355a370a1397804911'567 bytesVirustotal results 16/60 (26.67%) n/a
2017-09-01 11:45:08d1695c690caf5bb065b21eb5d11d7e40670'208 bytesVirustotal results 15/60 (25.00%) n/a

Unique dropped files: 7