Locky Distribution Site :: widenotions.com

Host Information

Locky Distribution Site:widenotions.com
Threat:Distribution Site
Malware:Locky
URL:http://widenotions.com/bh7188
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:ENOM, INC.
Nameserver(s):nsg1.namebrightdns.com
 nsg2.namebrightdns.com
Firstseen (UTC):2016-10-04 09:55:45
Lastseen (UTC):never

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
yes2019-10-13 01:31:012019-10-14 01:27:5523.20.239.12ec2-23-20-239-12.compute-1.amazonaws.comNot listedAS14618AMAZON-AES - Amazon.com, Inc., US- United States (US)
no2019-10-12 01:30:57never18.211.9.206ec2-18-211-9-206.compute-1.amazonaws.comNot listedAS14618AMAZON-AES - Amazon.com, Inc., US- United States (US)
no2016-12-07 15:11:442018-05-04 01:06:51198.54.114.176server228-1.web-hosting.comNot listedAS22612NAMECHEAP-NET - Namecheap, Inc., US- United States (US)
no2016-10-04 16:15:352016-12-03 14:31:43198.54.115.176s228.web-hosting.comNot listedAS22612NAMECHEAP-NET - Namecheap, Inc., US- United States (US)
no2018-05-05 01:45:062018-06-15 01:05:27198.54.117.200Not listedAS22612NAMECHEAP-NET - Namecheap, Inc., US- United States (US)
no2019-01-30 01:33:072019-07-27 01:27:49204.11.56.46Not listedAS40034CONFLUENCE-NETWORK-INC - Confluence Netw[...]- Virgin Islands, British (VG)
no2018-07-23 01:43:012019-01-29 01:33:04204.11.56.48Not listedAS40034CONFLUENCE-NETWORK-INC - Confluence Netw[...]- Virgin Islands, British (VG)
no2019-07-28 01:28:142019-09-04 01:29:25208.91.197.46Not listedAS40034CONFLUENCE-NETWORK-INC - Confluence Netw[...]- Virgin Islands, British (VG)

# IPs found: 8 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2016-10-04 16:15:2465dbaab40274bc0ac84d73bc6579bc23163'844 bytesVirustotal results 2/55 (3.64%) n/a

Unique dropped files: 1