Locky Distribution Site :: modelpayments.net

Host Information

Locky Distribution Site:modelpayments.net
Threat:Distribution Site
Malware:Locky
URL:http://modelpayments.net/7fg3g
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:WILD WEST DOMAINS, LLC
Firstseen (UTC):2016-10-28 11:20:13
Lastseen (UTC):never

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
no2018-06-12 01:52:11never184.168.221.64ip-184-168-221-64.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-05-13 01:26:492018-05-28 01:45:24184.168.221.67ip-184-168-221-67.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-05-22 01:46:38never184.168.221.69ip-184-168-221-69.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-05-12 01:27:212018-06-07 01:50:26184.168.221.72ip-184-168-221-72.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-08 01:50:46never184.168.221.81ip-184-168-221-81.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-05-27 01:49:09never184.168.221.84ip-184-168-221-84.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-06 01:50:43never184.168.221.90ip-184-168-221-90.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-14 01:53:45never184.168.221.91ip-184-168-221-91.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-05-16 01:48:222018-06-02 01:45:43184.168.221.94ip-184-168-221-94.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2016-10-28 12:55:422017-05-13 01:27:31192.254.206.5tel.telmedinc.comNot listedAS46606UNIFIEDLAYER-AS-1 - Unified Layer, US- United States (US)
no2018-05-24 01:45:072018-06-04 01:46:4350.63.202.66ip-50-63-202-66.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-13 01:48:032018-06-16 01:51:3650.63.202.67ip-50-63-202-67.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-05-15 01:47:532018-05-21 01:48:5050.63.202.70ip-50-63-202-70.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-05-11 01:26:412018-06-05 01:49:0750.63.202.73ip-50-63-202-73.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-09 01:48:32never50.63.202.78ip-50-63-202-78.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-10 01:48:422018-06-11 01:49:5050.63.202.85ip-50-63-202-85.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)

# IPs found: 16 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2016-10-29 01:00:3020db9dbf8ce79e80f8b0a0c2b9390a33237'568 bytesVirustotal results 5/60 (8.33%) # Not authorized
2016-10-28 12:52:1686de7c69b610ccfe56143f2cd6a53158266'240 bytesVirustotal results 0/55 (0.00%) n/a

Unique dropped files: 2