Locky Distribution Site :: media-shoten.com

Host Information

Locky Distribution Site:media-shoten.com
Threat:Distribution Site
Malware:Locky
URL:http://media-shoten.com/9y878hi
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:GMO INTERNET, INC. DBA ONAMAE.COM
Firstseen (UTC):2016-11-10 15:47:26
Lastseen (UTC):never

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
no2018-04-23 02:12:272018-04-30 02:14:59103.224.182.250lb-182-250.above.comNot listedAS133618TRELLIAN-AS-AP Trellian Pty. Limited, AU- Australia (AU)
no2017-05-06 01:38:242018-05-01 02:17:00103.224.212.222lb-212-222.above.comNot listedAS133618TRELLIAN-AS-AP Trellian Pty. Limited, AU- Australia (AU)
no2016-11-10 15:52:532016-11-21 22:27:56113.192.235.136113x192x235x136.21-host.comNot listedAS7514MEX Computer Engineering & Consulting, L[...]- Japan (JP)
no2017-05-01 01:45:052017-05-05 01:38:46185.53.178.12Not listedAS61969TEAMINTERNET-AS, DE- Germany (DE)
no2017-05-21 01:30:442018-02-12 02:15:55192.184.12.62Not listedAS32421BLCC - Black Lotus Communications, US- United States (US)
no2016-11-22 02:23:492016-12-19 12:11:56192.64.147.141192.64.147.141.voodoo.comNot listedAS19867VOODOO1 - Voodoo.com, Inc, US- United States (US)
no2016-11-22 02:23:482016-12-19 12:11:5623.253.164.103Not listedAS19994RACKSPACE - Rackspace Hosting, US- United States (US)
no2017-05-22 01:31:152018-03-26 02:23:2370.32.1.32ip-70.32.1.32.hosted.by.gigenet.comNot listedAS32181ASN-GIGENET - GigeNET, US- United States (US)

# IPs found: 8 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2016-11-10 08:46:30cf318e9ec4550c4cecbd7f9130034d2d311'296 bytesVirustotal results 5/56 (8.93%) n/a

Unique dropped files: 1