Locky C2 :: bkdjvmmkwgkvgw.su

Host Information

Locky C2:bkdjvmmkwgkvgw.su
Threat:C2
Malware:Locky
URL:http://bkdjvmmkwgkvgw.su/userinfo.php
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:NAUNET-REG-FID
Firstseen (UTC):2016-05-20 07:38:40
Lastseen (UTC):2016-05-20 09:22:12

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky C2. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
yes2016-05-20 08:12:032016-05-20 14:44:5891.219.31.1414.31.219.91.colo.ukrservers.comNot listedAS199427DATAHARBOUR-AS , RU- Russian Federation (RU)

# IPs found: 1 (max. 25)

Referencing malware samples

Latest 100 malware binaries referencing this Locky C2:

Firstseen (UTC)MD5 hashFilesizeVTLocky C2 URL
2016-05-20 05:48:5729d8873d096c9abb3e9a6584c992ee60225'280 bytesVirustotal results 14/57 (24.56%) http://bkdjvmmkwgkvgw.su/userinfo.php
2016-05-19 17:36:39ed61e97fd5d3d6dff76544ed09158ef8154'112 bytesVirustotal results 38/57 (66.67%) http://bkdjvmmkwgkvgw.su/userinfo.php

Referencing malware samples: 2