Locky Distribution Site :: seo-app.nl

Host Information

Locky Distribution Site:seo-app.nl
Threat:Distribution Site
Malware:Locky
URL:http://seo-app.nl/rwo9c2
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:Argeweb
Nameserver(s):ns1.argewebhosting.eu
 ns2.argewebhosting.com
 ns3.argewebhosting.nl
Firstseen (UTC):2016-12-01 08:31:32
Lastseen (UTC):never

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
yes2018-01-29 01:22:092019-06-24 02:49:2452.57.147.144ec2-52-57-147-144.eu-central-1.compute.amazonaws.comNot listedAS16509AMAZON-02 - Amazon.com, Inc., US- Germany (DE)
no2017-03-29 01:46:182018-01-27 01:20:41145.131.21.95ahv-id-17503.vps.awcloud.nlNot listedAS8315AMSIO, NL- Netherlands (NL)
no2016-12-01 13:40:372017-03-28 01:45:45145.131.3.68ahv-id-16252.vps.awcloud.nlNot listedAS8315AMSIO , NL- Netherlands (NL)
no2018-01-28 01:22:10never95.85.5.194pmikhaylov-playground.plesk.spaceNot listedAS14061DIGITALOCEAN-ASN - DigitalOcean, LLC, US- Netherlands (NL)

# IPs found: 4 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2016-12-01 13:40:35e446139e36c0550f51daf0d1099e2426282'318 bytesVirustotal results 1/54 (1.85%) n/a

Unique dropped files: 1