Locky Distribution Site :: mecnun.biz

Host Information

Locky Distribution Site:mecnun.biz
Threat:Distribution Site
Malware:Locky
URL:http://mecnun.biz/f5nguh1
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:LISTED
Domain Registar:PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Firstseen (UTC):2016-11-09 15:25:29
Lastseen (UTC):never

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
no2018-09-07 08:25:402018-09-09 08:25:59199.115.115.116Not listedAS30633LEASEWEB-USA-WDC-01 - Leaseweb USA, Inc.[...]- United States (US)
no2018-08-12 08:29:142019-01-15 08:20:1846.166.182.63.Not listedAS43350NFORCE , NL- Netherlands (NL)
no2018-07-27 08:29:042019-01-01 08:17:2046.166.182.62.Not listedAS43350NFORCE , NL- Netherlands (NL)
no2018-07-23 08:29:532019-02-20 08:12:4646.166.182.56Not listedAS43350NFORCE , NL- Netherlands (NL)
no2018-07-25 08:30:122019-02-13 08:11:5446.166.182.55Not listedAS43350NFORCE , NL- Netherlands (NL)
no2018-08-29 08:26:162019-02-21 08:10:2546.166.182.54Not listedAS43350NFORCE , NL- Netherlands (NL)
no2018-08-01 08:29:542019-03-04 08:05:2246.166.182.53Not listedAS43350NFORCE , NL- Netherlands (NL)
no2018-07-28 08:30:262019-02-14 08:09:5946.166.182.52Not listedAS43350NFORCE , NL- Netherlands (NL)
no2017-10-27 02:12:352017-12-07 07:55:23209.99.40.221209-99-40-221.fwd.datafoundry.comNot listedAS40034TEXASNET-ASN - YHC Corporation, US- United States (US)
no2018-07-26 08:29:072019-02-11 08:08:1346.166.182.64.Not listedAS43350NFORCE , NL- Netherlands (NL)
no2017-02-16 01:46:382017-02-24 01:51:31194.67.215.18server.datawap.azNot listedAS48666AS-MAROSNET Moscow, Russia, RU- Russian Federation (RU)
no2017-01-20 07:03:372017-06-12 01:40:11194.67.213.184server.nsdata.inNot listedAS48666AS-MAROSNET Moscow, Russia, RU- Russian Federation (RU)
no2016-11-24 17:43:352017-01-19 07:08:54194.67.199.214server.nsdataa.ruNot listedAS48666AS-MAROSNET Moscow, Russia, RU- Russian Federation (RU)
no2017-03-25 01:55:222017-03-26 01:52:49193.124.187.232serverim.ruNot listedAS48666AS-MAROSNET Moscow, Russia, RU- Russian Federation (RU)
no2018-06-07 02:22:252018-06-18 02:16:28192.184.12.62Not listedAS32421BLCC - Black Lotus Communications, US- United States (US)
no2018-11-12 08:20:49never192.155.108.158Not listedAS29066VELIANET-AS velia.net Internetdienste Gm[...]- United States (US)
no2018-07-24 08:28:42never192.155.108.154Not listedAS29066VELIANET-AS velia.net Internetdienste Gm[...]- United States (US)
no2018-11-11 08:27:59never192.155.108.148Not listedAS29066VELIANET-AS velia.net Internetdienste Gm[...]- United States (US)
no2019-03-12 08:07:502019-03-29 08:03:5650.63.202.79ip-50-63-202-79.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-11-22 08:18:572019-02-17 08:10:1596.47.230.7096.47.230.70.static.rivalserver.comNot listedAS8100ASN-QUADRANET-GLOBAL - QuadraNet Enterpr[...]- United States (US)
no2018-12-28 08:19:172019-03-05 08:05:5796.47.230.6996.47.230.69.static.rivalserver.comNot listedAS8100ASN-QUADRANET-GLOBAL - QuadraNet Enterpr[...]- United States (US)
no2018-12-05 08:22:192019-02-25 08:09:2296.47.230.6896.47.230.68.static.rivalserver.comNot listedAS8100ASN-QUADRANET-GLOBAL - QuadraNet Enterpr[...]- United States (US)
no2018-11-18 08:22:062019-02-19 08:09:5896.47.230.6796.47.230.67.static.rivalserver.comNot listedAS8100ASN-QUADRANET-GLOBAL - QuadraNet Enterpr[...]- United States (US)
no2018-03-09 02:29:472018-06-17 02:20:2170.32.1.32ip-70.32.1.32.hosted.by.gigenet.comNot listedAS32181ASN-GIGENET - GigeNET, US- United States (US)
no2019-03-07 08:09:152019-03-31 08:07:5650.63.202.95ip-50-63-202-95.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)

# IPs found: 25 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2016-11-09 16:12:09c2da2dbe8fab6f07ddd70a82aae7299c122'368 bytesVirustotal results 14/57 (24.56%) n/a

Unique dropped files: 1