Locky Distribution Site :: vibrantdeal.com

Host Information

Locky Distribution Site:vibrantdeal.com
Threat:Distribution Site
Malware:Locky
URL:http://vibrantdeal.com/7fg3g
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Nameserver(s):gds1.namepull.com
 gds2.namepull.com
Firstseen (UTC):2016-10-28 10:47:21
Lastseen (UTC):never

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
yes2018-07-22 07:04:192019-07-16 06:50:25178.128.155.112Not listedAS14061DIGITALOCEAN-ASN - DigitalOcean, LLC, US- Greece (GR)
no2017-10-27 01:52:482018-06-09 01:50:5350.63.202.25ip-50-63-202-25.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-02-01 01:55:122018-02-10 01:56:0150.63.202.12ip-50-63-202-12.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-10-31 01:56:042017-11-15 01:51:4750.63.202.13ip-50-63-202-13.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-11-01 01:57:092018-07-04 07:18:0750.63.202.14ip-50-63-202-14.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-03-06 01:57:17never50.63.202.15ip-50-63-202-15.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-02-22 01:52:522018-05-07 07:07:1750.63.202.16ip-50-63-202-16.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-01-22 01:54:002018-06-23 07:02:0250.63.202.17ip-50-63-202-17.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-07-10 07:03:592018-07-16 07:01:1150.63.202.18ip-50-63-202-18.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-01-14 01:56:23never50.63.202.19ip-50-63-202-19.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-10-28 01:51:062018-05-26 01:48:5750.63.202.2ip-50-63-202-2.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-03-28 01:55:092018-06-06 01:53:0350.63.202.21ip-50-63-202-21.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-11-17 01:49:412018-07-13 07:02:4850.63.202.22ip-50-63-202-22.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-02-24 01:55:512018-03-13 01:54:0750.63.202.23ip-50-63-202-23.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-04-28 01:50:24never50.63.202.24ip-50-63-202-24.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-10-24 01:54:022018-02-26 01:57:1350.63.202.10ip-50-63-202-10.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-01-12 02:01:362018-04-06 01:55:5050.63.202.26ip-50-63-202-26.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-02-19 01:56:43never50.63.202.28ip-50-63-202-28.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-11-23 01:47:59never50.63.202.29ip-50-63-202-29.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-07-05 07:25:53never50.63.202.3ip-50-63-202-3.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-01-10 01:58:432018-07-15 07:00:5550.63.202.30ip-50-63-202-30.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-01-28 01:57:032018-03-18 01:55:0050.63.202.31ip-50-63-202-31.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-11-27 01:51:112018-03-16 02:06:5750.63.202.4ip-50-63-202-4.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-07-17 07:00:05never50.63.202.41ip-50-63-202-41.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-04-25 01:49:122018-04-27 01:48:0950.63.202.6ip-50-63-202-6.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)

# IPs found: 25 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2016-10-29 01:00:3020db9dbf8ce79e80f8b0a0c2b9390a33237'568 bytesVirustotal results 5/60 (8.33%) # Not authorized
2016-10-28 10:52:13e6151a0259f7e2b29fd315b542bc9ba2266'240 bytesVirustotal results 0/53 (0.00%) n/a

Unique dropped files: 2