Locky Distribution Site :: miss-green.ru

Host Information

Locky Distribution Site:miss-green.ru
Threat:Distribution Site
Malware:Locky
URL:http://miss-green.ru/image/flags/wss.exe
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:NAUNET-RU
Nameserver(s):ns1.j-dns.ru
 ns2.j-dns.ru
 ns3.j-dns.ru
 ns4.j-dns.ru
Firstseen (UTC):2016-03-27 09:19:39
Lastseen (UTC):never

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
yes2016-03-27 18:12:042017-05-13 01:57:28146.185.243.134Not listedAS44050PIN-AS Petersburg Internet Network ltd.,[...]- Russian Federation (RU)
no2016-03-27 09:19:392016-03-27 17:58:41178.63.56.206static.206.56.63.178.clients.your-server.deNot listedAS24940 HETZNER-AS Hetzner Online GmbH,DE- Germany (DE)

# IPs found: 2 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2016-04-06 19:51:11a9d5e84921a829ce9a619f49146437b410'046 bytesn/aERROR: Too many connections
2016-04-02 21:10:52f4f4d826934a747166d64b7f097ca0ec10'036 bytesn/aERROR: Too many connections
2016-03-27 17:58:41f065a465b2fa660766497742ed350c98108'032 bytesVirustotal results 22/58 (37.93%) n/a
2016-03-27 09:28:547c9bfec0c0f1756c76088a45b157148e117'511 bytesVirustotal results 28/58 (48.28%) Locky

Unique dropped files: 4