Locky Distribution Site :: irnetshop.com

Host Information

Locky Distribution Site:irnetshop.com
Threat:Distribution Site
Malware:Locky
URL:http://irnetshop.com/dfvltrouq
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:REALTIME REGISTER BV
Firstseen (UTC):2016-11-22 08:29:32
Lastseen (UTC):never

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
no2017-02-12 06:10:122017-05-13 02:16:31104.31.64.212Not listedAS13335CLOUDFLARENET - CloudFlare, Inc., US- United States (US)
no2017-02-12 06:10:092017-05-13 02:16:41104.31.65.212Not listedAS13335CLOUDFLARENET - CloudFlare, Inc., US- United States (US)
no2016-11-22 10:19:372017-01-19 05:49:26149.202.138.70ip70.ip-149-202-138.euNot listedAS16276OVH , FR- France (FR)
no2018-05-12 01:15:28never52.213.114.86ec2-52-213-114-86.eu-west-1.compute.amazonaws.comNot listedAS16509AMAZON-02 - Amazon.com, Inc., US- Ireland (IE)
no2017-01-20 05:51:502019-01-13 03:37:2678.46.113.238mailserver49.mylittledatacenter.comNot listedAS24940HETZNER-AS , DE- Germany (DE)

# IPs found: 5 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2016-11-22 10:19:3684d63ca4fded9b3f3b5e9169b6a600b6119'296 bytesVirustotal results 3/54 (5.56%) n/a

Unique dropped files: 1