Locky Distribution Site :: keshamrit.com

Host Information

Locky Distribution Site:keshamrit.com
Threat:Distribution Site
Malware:Locky
URL:http://keshamrit.com/7fg3g
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Nameserver(s):ns05.domaincontrol.com
 ns06.domaincontrol.com
Firstseen (UTC):2016-10-28 09:45:15
Lastseen (UTC):never

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
yes2019-03-09 07:49:092019-07-16 07:45:5950.63.202.34ip-50-63-202-34.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-03-15 02:03:542018-11-05 08:08:2850.63.202.40ip-50-63-202-40.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-09-24 08:02:142018-11-03 08:09:0750.63.202.49ip-50-63-202-49.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-08-29 07:58:462019-03-30 07:47:1550.63.202.48ip-50-63-202-48.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-02-16 02:02:582018-11-06 08:13:5950.63.202.47ip-50-63-202-47.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2019-03-29 07:49:592019-06-22 07:50:3850.63.202.46ip-50-63-202-46.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2019-04-04 07:52:402019-05-24 07:52:3650.63.202.45ip-50-63-202-45.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-04-12 01:59:392019-07-12 07:58:3150.63.202.44ip-50-63-202-44.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-01-30 02:05:572019-06-11 07:50:5950.63.202.43ip-50-63-202-43.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-02-12 02:06:51never50.63.202.42ip-50-63-202-42.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-13 01:58:362018-08-19 08:00:4750.63.202.50ip-50-63-202-50.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-02-06 02:02:362018-07-31 08:01:1350.63.202.38ip-50-63-202-38.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-03-04 02:04:472019-01-10 07:57:3750.63.202.37ip-50-63-202-37.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-09-11 07:59:402019-06-27 07:57:2550.63.202.36ip-50-63-202-36.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-08 02:00:152018-06-11 02:03:2350.63.202.33ip-50-63-202-33.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-10-05 07:57:25never50.63.202.32ip-50-63-202-32.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2016-10-30 15:32:512017-12-08 07:45:49209.99.40.223209-99-40-223.fwd.datafoundry.comNot listedAS3900TEXASNET-ASN - YHC Corporation, US- United States (US)
no2018-01-31 02:00:512019-01-09 09:32:1950.63.202.60ip-50-63-202-60.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2016-10-28 11:11:532017-10-28 01:58:3950.87.132.22250-87-132-222.unifiedlayer.comNot listedAS46606UNIFIEDLAYER-AS-1 - Unified Layer, US- United States (US)
no2019-02-07 07:49:46never50.63.202.88ip-50-63-202-88.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2019-02-02 07:51:08never50.63.202.82ip-50-63-202-82.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2019-02-05 07:53:062019-02-24 07:50:5150.63.202.77ip-50-63-202-77.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2019-02-01 07:51:372019-02-28 07:46:1450.63.202.68ip-50-63-202-68.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-03-10 02:02:112019-05-30 07:51:4750.63.202.63ip-50-63-202-63.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2019-07-02 07:52:522019-07-08 07:52:2050.63.202.62ip-50-63-202-62.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)

# IPs found: 25 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2016-10-29 01:00:3020db9dbf8ce79e80f8b0a0c2b9390a33237'568 bytesVirustotal results 5/60 (8.33%) # Not authorized
2016-10-28 10:52:13e6151a0259f7e2b29fd315b542bc9ba2266'240 bytesVirustotal results 0/53 (0.00%) n/a

Unique dropped files: 2