Locky Distribution Site :: mecnun.biz

Host Information

Locky Distribution Site:mecnun.biz
Threat:Distribution Site
Malware:Locky
URL:http://mecnun.biz/f5nguh1
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Nameserver(s):ns43.domaincontrol.com
 ns44.domaincontrol.com
Firstseen (UTC):2016-11-09 15:25:29
Lastseen (UTC):never

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
yes2019-03-09 08:07:162019-03-21 08:05:11184.168.221.87ip-184-168-221-87.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-07-23 08:29:532019-02-20 08:12:4646.166.182.56Not listedAS43350NFORCE , NL- Netherlands (NL)
no2018-07-27 08:29:042019-01-01 08:17:2046.166.182.62.Not listedAS43350NFORCE , NL- Netherlands (NL)
no2018-07-25 08:30:122019-02-13 08:11:5446.166.182.55Not listedAS43350NFORCE , NL- Netherlands (NL)
no2018-08-29 08:26:162019-02-21 08:10:2546.166.182.54Not listedAS43350NFORCE , NL- Netherlands (NL)
no2018-08-01 08:29:542019-03-04 08:05:2246.166.182.53Not listedAS43350NFORCE , NL- Netherlands (NL)
no2018-07-28 08:30:262019-02-14 08:09:5946.166.182.52Not listedAS43350NFORCE , NL- Netherlands (NL)
no2017-10-27 02:12:352017-12-07 07:55:23209.99.40.221209-99-40-221.fwd.datafoundry.comNot listedAS3900TEXASNET-ASN - YHC Corporation, US- United States (US)
no2018-09-07 08:25:402018-09-09 08:25:59199.115.115.116Not listedAS30633LEASEWEB-USA-WDC-01 - Leaseweb USA, Inc.[...]- United States (US)
no2017-02-16 01:46:382017-02-24 01:51:31194.67.215.18server.datawap.azNot listedAS48666AS-MAROSNET Moscow, Russia, RU- Russian Federation (RU)
no2017-01-20 07:03:372017-06-12 01:40:11194.67.213.184server.nsdata.inNot listedAS48666AS-MAROSNET Moscow, Russia, RU- Russian Federation (RU)
no2016-11-24 17:43:352017-01-19 07:08:54194.67.199.214server.nsdataa.ruNot listedAS48666AS-MAROSNET Moscow, Russia, RU- Russian Federation (RU)
no2017-03-25 01:55:222017-03-26 01:52:49193.124.187.232serverim.ruNot listedAS48666AS-MAROSNET Moscow, Russia, RU- Russian Federation (RU)
no2018-06-07 02:22:252018-06-18 02:16:28192.184.12.62Not listedAS32421BLCC - Black Lotus Communications, US- United States (US)
no2018-11-12 08:20:49never192.155.108.158Not listedAS29066VELIANET-AS velia.net Internetdienste Gm[...]- United States (US)
no2018-07-24 08:28:42never192.155.108.154Not listedAS29066VELIANET-AS velia.net Internetdienste Gm[...]- United States (US)
no2018-11-11 08:27:59never192.155.108.148Not listedAS29066VELIANET-AS velia.net Internetdienste Gm[...]- United States (US)
no2018-11-22 08:18:572019-02-17 08:10:1596.47.230.7096.47.230.70.static.rivalserver.comNot listedAS8100ASN-QUADRANET-GLOBAL - QuadraNet Enterpr[...]- United States (US)
no2018-08-12 08:29:142019-01-15 08:20:1846.166.182.63.Not listedAS43350NFORCE , NL- Netherlands (NL)
no2018-07-26 08:29:072019-02-11 08:08:1346.166.182.64.Not listedAS43350NFORCE , NL- Netherlands (NL)
no2017-06-13 01:38:592017-06-20 01:37:5446.17.46.13Not listedAS51659ASBAXET, RU- Russian Federation (RU)
no2016-11-09 16:12:252016-11-22 05:06:3146.17.47.38vt.diecastingpowdercoating.infoNot listedAS51659ASBAXET , RU- Russian Federation (RU)
no2016-11-22 11:16:382016-11-24 10:30:3446.29.160.48Not listedAS51659ASBAXET , RU- Russian Federation (RU)
no2019-03-11 08:09:51never50.63.202.68ip-50-63-202-68.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2019-03-12 08:07:50never50.63.202.79ip-50-63-202-79.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)

# IPs found: 25 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2016-11-09 16:12:09c2da2dbe8fab6f07ddd70a82aae7299c122'368 bytesVirustotal results 14/57 (24.56%) n/a

Unique dropped files: 1