Locky Distribution Site :: pattumalamatha.com
Host Information
Locky Distribution Site: | pattumalamatha.com | |
---|---|---|
Threat: | Distribution Site | |
Malware: | Locky | |
Host Status: | ||
Blacklist check: | Spamhaus DBL: | |
SURBL: | ||
Domain Registar: | GODADDY.COM, LLC | |
Firstseen (UTC): | 2016-10-05 10:08:24 | |
Lastseen (UTC): | never |
Ransomware URLs
The table below shows all associated Ransomware URLs located on this host.
Firstseen (UTC) | URL (?URL assocaited with this Ransomware. The leading dots (Red, Green, Grey) indicate whether the URL is active or not. Red = Online Green = Offline Grey = Unknown) | Threat | Malware |
---|---|---|---|
2016-11-22 12:34:55 | http://pattumalamatha.com/biwkk3sp | ||
2016-10-05 10:08:24 | http://pattumalamatha.com/e7r2v1t |
# of URLs: 2
Associated IP addresses
The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.
Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address). yes = Active A record no = Historical record) | Firstseen (UTC) | Lastseen (UTC) | IP address | Hostname | SBL | AS number | AS name | Country |
---|---|---|---|---|---|---|---|---|
no | 2018-02-21 01:28:49 | 2018-03-02 01:51:43 | 50.63.202.45 | ip-50-63-202-45.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2017-09-29 01:01:42 | 2018-03-18 01:28:02 | 50.63.202.55 | ip-50-63-202-55.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2017-11-21 01:21:11 | 2018-06-01 01:25:46 | 50.63.202.54 | ip-50-63-202-54.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2018-01-27 01:50:00 | 2018-04-10 01:52:49 | 50.63.202.53 | ip-50-63-202-53.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2018-01-04 01:51:57 | 2018-03-08 01:28:46 | 50.63.202.52 | ip-50-63-202-52.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2018-03-17 01:51:26 | 2018-04-09 01:26:00 | 50.63.202.50 | ip-50-63-202-50.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2018-02-23 01:48:21 | 2018-02-27 01:29:38 | 50.63.202.49 | ip-50-63-202-49.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2018-01-04 01:26:40 | 2018-06-04 01:45:50 | 50.63.202.48 | ip-50-63-202-48.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2017-10-03 01:49:41 | 2018-07-07 03:20:29 | 50.63.202.47 | ip-50-63-202-47.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2018-02-01 01:28:59 | 2018-05-06 03:14:25 | 50.63.202.46 | ip-50-63-202-46.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2017-10-29 01:18:57 | 2018-02-26 01:28:57 | 50.63.202.57 | ip-50-63-202-57.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2018-02-15 01:51:32 | 2018-06-21 03:16:01 | 50.63.202.43 | ip-50-63-202-43.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2018-01-12 01:27:46 | 2018-02-17 01:28:30 | 50.63.202.41 | ip-50-63-202-41.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2017-10-04 01:48:18 | 2018-03-20 01:51:13 | 50.63.202.40 | ip-50-63-202-40.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2018-03-21 01:27:42 | 2018-03-27 01:53:26 | 50.63.202.39 | ip-50-63-202-39.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2017-09-27 01:44:47 | 2018-06-06 01:47:47 | 50.63.202.38 | ip-50-63-202-38.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2017-12-22 01:27:12 | 2018-03-19 01:27:25 | 50.63.202.37 | ip-50-63-202-37.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2017-10-28 01:17:01 | 2018-07-03 03:17:47 | 50.63.202.36 | ip-50-63-202-36.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2017-09-26 02:34:33 | 2018-03-12 01:28:07 | 50.63.202.35 | ip-50-63-202-35.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2018-08-08 07:21:34 | never | 50.63.202.69 | ip-50-63-202-69.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2019-06-25 07:02:30 | 2019-06-26 03:17:28 | 89.35.39.67 | Not listed | AS44220 | PARFUMURI-FEMEI-AS, RO | ![]() | |
no | 2019-06-29 07:05:55 | never | 89.35.39.65 | mx1.dartxtree.com | Not listed | AS44220 | PARFUMURI-FEMEI-AS, RO | ![]() |
no | 2019-06-26 07:04:24 | never | 89.35.39.50 | Not listed | AS44220 | PARFUMURI-FEMEI-AS, RO | ![]() | |
no | 2018-07-09 03:20:02 | 2018-07-29 07:20:24 | 50.63.202.93 | ip-50-63-202-93.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
no | 2018-08-07 03:20:16 | never | 50.63.202.92 | ip-50-63-202-92.ip.secureserver.net | Not listed | AS26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...] | ![]() |
# IPs found: 25 (max. 25)
Dropped files
Latest 100 files (malware samples) dropped by this distribution site.
Firstseen (UTC) | MD5 hash | Filesize | VT | Signature |
---|---|---|---|---|
2016-11-22 17:13:48 | e1be189f5c2568b36ca4d2a5a695929d | 184'587 bytes | ![]() | n/a |
Unique dropped files: 1